I am in the process of updating my résumé. Not because I’m looking for a job[1], but because I like to feature my résumé on my website and the current published copy doesn’t reflect my pivot from engineering management to an individual contributor role two years ago. I feel a little bit weird about the […]
I gave an opening keynote at the FIDO Alliance’s “Authenticate” conference a few weeks ago! Although it featured timely strategies and tips for professionals deploying passkeys, my primary goal was to explain, as clearly as I can, why passkeys are important and how we should use them to reduce the harm that passwords cause. [ […]
I recently had the privilege and pleasure of co-writing a post on the Swift programming language blog about Apple’s Password Monitoring service and its re-write from Java to Swift. The positive impact on memory use and overall throughput were stunning. Give it a read!
Magic links, those emailed one-time login links, are annoying and inconvenient for folks who use a password manager, but they radically accept some fundamental truths about signing in for everyone else. By layering passkeys on top of magic links, websites can provide a seamless authentication experience for all users.
This post briefly summarizes part of a talk I gave in 2018. All information in this post has been accessible on YouTube since then. There is no new information or news in this post. On Mastodon recently, jsveningsson@mastodon.social asked me: Having an annoying argument on Threads about Apple generated passwords. Every iOS Password (like hupvEw-fodne1-qabjyg) […]
Note: This post is intended for people interested in using and contributing to the Password Manager Resources open source project. I am writing it in a personal capacity, as a maintainer and contributor to an open source project that I am passionate about. I recently contributed two new quirks to the Password Manager Resources open […]
I’ve never attended a conference before in a personal capacity[1]. Sure, I’ve worked events my employer has put on and spoken at conferences about what I do professionally, but I’d never paid money to show up somewhere just to learn, get inspired, or hang out. That changed a few weeks ago, when I visited Portland, […]
Important Note: Although I work at Apple and am deeply involved in the creation of its new Passwords app, in this post I am speaking only for myself and not for Apple. There is no “news” in this post, or any kind of “inside scoop”. My intention is to help the kind of person who […]
In the last few months, I’ve made some important and positive changes in my life. I’ve been letting people know when I catch up with them, but I’d like the changes to be in the open. Hence this post, which is a self-indulgent update on my life for people who either care about me or […]
Some background on me: I’m a software engineer working in what I call “usable security”. I’m passionate about this field because advancements can tangibly improve people’s lives, making their computing experiences easier and accounts more secure at the same time. This post contains some of my personal thoughts. It does not represent anyone else or […]
Update: I’m doing an AMA (ask me anything) on Mastodon today, December 18. Over the last week, my opinion of the Mastodon project and software, as well as the “Fediverse”, has completely changed. I was pretty skeptical of it, but after giving it a chance, I’m participating and having fun. Let’s rewind back to the […]