Topic: user authentication

  • Chrome adds its strongest account takeover protection yet

    Chrome adds its strongest account takeover protection yet

    Google has introduced device-bound session credentials (DBSCs) in Chrome, which generate a hardware-based encryption key stored in secure areas like the TPM (Windows) or Secure Enclave (macOS/iOS) to protect against session cookie theft. This defense targets the growing attack trend where crimina...

    Read More »
  • Google Search tests sign-in requirement for more results

    Google Search tests sign-in requirement for more results

    Google is testing a new verification method that replaces CAPTCHA with a sign-in wall, requiring users to log into their Google accounts to view more search results beyond the first few pages. This change could significantly disrupt SEO tracking platforms and third-party scraping tools like SerpA...

    Read More »
  • Google mandates passkeys for Ads API users

    Google mandates passkeys for Ads API users

    Starting August 5th, Google will require passkeys for generating new OAuth 2.0 refresh tokens in the Google Ads API, replacing password-only logins and traditional two-factor methods. Existing OAuth refresh tokens will continue to work without reauthorization, but newly created passkeys may have ...

    Read More »
  • Netflix now requires unique email for each user profile

    Netflix now requires unique email for each user profile

    Netflix now requires each user profile under a single subscription to have a unique email address, a permanent change that began rolling out on June 15, 2026. This update caused confusion for a user whose father was locked out of his account and forced to create a separate login to continue using...

    Read More »
  • Cloudflare partners with Chrome, Firefox, Edge on privacy-first anti-bot tool

    Cloudflare partners with Chrome, Firefox, Edge on privacy-first anti-bot tool

    Cloudflare, Mozilla Firefox, Google Chrome, and Microsoft Edge are collaborating on Private Access Control Tokens, a new protocol that verifies human web traffic without collecting personal data or requiring CAPTCHAs. The system embeds verification directly into the browser, issuing anonymous tok...

    Read More »
  • Roblox exec: Age verification must go beyond a checkbox

    Roblox exec: Age verification must go beyond a checkbox

    Roblox is using video selfie-based facial age estimation technology to verify users' ages, claiming it can estimate a child's age within 1.4 years and that even a fake mustache failed to bypass the system. The company believes self-declaration of age is no longer sufficient, with the technology e...

    Read More »
  • Google Ads API Mandates Multi-Factor Authentication

    Google Ads API Mandates Multi-Factor Authentication

    Google Ads will enforce mandatory multi-factor authentication (MFA) for all new user logins via its API starting April 21, 2026, enhancing account security. The requirement applies to new OAuth 2.0 authentications, prompting users to set up 2-step verification, but existing tokens and service acc...

    Read More »
  • Reddit Adds Human Verification to Combat Bot Activity

    Reddit Adds Human Verification to Combat Bot Activity

    Reddit is implementing a new human verification checkpoint for accounts flagged as potential bots to combat spam and coordinated manipulation. This aggressive layer of defense aims to disrupt malicious bots that spread misinformation, inflate engagement, or harass users. The policy is part of a b...

    Read More »
  • Reddit CEO Reveals Hidden Benefit of Face ID and Touch ID

    Reddit CEO Reveals Hidden Benefit of Face ID and Touch ID

    Passkeys are replacing passwords, offering a simpler and more secure login method by integrating with existing biometric systems like Touch ID and Face ID. They eliminate common password vulnerabilities by using public-key cryptography, where a private key stays on the user's device and is protec...

    Read More »
  • Accertify's Attack State Fights Credential Stuffing & ATO

    Accertify's Attack State Fights Credential Stuffing & ATO

    Accertify has launched a new feature called **Attack State** to combat automated credential stuffing and account takeover attacks, which threaten financial security and customer trust. The system analyzes login patterns in real-time to detect coordinated assaults and can trigger adaptive defenses...

    Read More »
  • Loblaw Data Breach: Customer Information Exposed

    Loblaw Data Breach: Customer Information Exposed

    Loblaw Companies Ltd. experienced a security breach where unauthorized access to a limited number of customer accounts was gained through credential stuffing, though its own systems were not directly compromised. The company has logged all users out as a precaution and advises customers to update...

    Read More »
  • Google Maps Hides Reviews, Images for Signed-Out Users

    Google Maps Hides Reviews, Images for Signed-Out Users

    Google Maps now restricts key community features like reviews and photos for users browsing without a Google account, creating a significant gap between logged-in and signed-out experiences. The change is triggered by factors like technical issues or unusual traffic, with Google suggesting that s...

    Read More »
  • Germ launches as Bluesky's first private messenger integration

    Germ launches as Bluesky's first private messenger integration

    Bluesky has integrated a new end-to-end encrypted messaging service, Germ DM, directly into its platform, marking the first private messenger native to the Bluesky app and showcasing the advantage of its open ecosystem. The service, built by startup Germ Network, uses the Messaging Layer Security...

    Read More »
  • US Cargo Firm Exposes Shipping Systems and Customer Data Online

    US Cargo Firm Exposes Shipping Systems and Customer Data Online

    Security experts warn that cyberattacks on logistics firms are enabling large-scale cargo theft, creating a dangerous alliance between hackers and organized crime that threatens global supply chains. A researcher discovered severe vulnerabilities in Bluspark Global's shipping software, including ...

    Read More »
  • Kohler's Smart Toilet Cameras Claim E2EE Despite Data Access

    Kohler's Smart Toilet Cameras Claim E2EE Despite Data Access

    Kohler's smart toilet camera, which analyzes waste for health insights, claims to use end-to-end encryption (E2EE) for privacy, but experts challenge this as the company itself can decrypt and access the sensitive data. The company's interpretation of E2EE means data is encrypted in transit to it...

    Read More »
  • Netflix Ends Casting Support for Most TVs

    Netflix Ends Casting Support for Most TVs

    Netflix has deliberately restricted Google Cast support, now limiting it to premium, ad-free subscribers and a narrow set of older hardware. This move aligns with Netflix's broader strategy to curb password sharing and tie viewing to specific devices and accounts within a household. The change ef...

    Read More »
  • Wyze's Budget Smart Lock Now Has Built-In Wi-Fi for Free

    Wyze's Budget Smart Lock Now Has Built-In Wi-Fi for Free

    Wyze has released the Lock Bolt v2, an upgraded smart lock with built-in Wi-Fi at the same $79.98 price, enabling remote control via app or voice assistants for enhanced accessibility. The new model retains key features like a fast fingerprint reader and local biometric storage, while adding an i...

    Read More »
  • X Unveils Encrypted Chat for Private Messaging

    X Unveils Encrypted Chat for Private Messaging

    X has launched a new Chat feature with end-to-end encryption for private conversations, enhancing user privacy and adding support for video/voice calls, disappearing messages, and secure file sharing. The rollout is currently available on iOS and web, with Android to follow, and includes migratio...

    Read More »
  • YouTube Expands AI Age Verification to More Users

    YouTube Expands AI Age Verification to More Users

    YouTube is expanding AI-powered age verification to restrict underage access to mature content, causing frustration among some users due to its intrusiveness. Users flagged as potentially under 18 must verify their age via ID, selfie, or credit card or accept account limitations like blocked age-...

    Read More »
  • Brave Exposes Critical AI Browser Security Flaws

    Brave Exposes Critical AI Browser Security Flaws

    Brave uncovered critical security flaws in AI browsers like Perplexity Comet and Fellou, where malicious websites can hijack AI assistants to access sensitive user accounts and data through indirect prompt injection attacks. These vulnerabilities allow attackers to embed hidden commands in webpag...

    Read More »