# passwords

A password is a memorized secret used to authenticate an identity or verify access authorization.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Revolut phishing texts appear days after data breach

DevFeed: [Revolut phishing texts appear days after data breach](<https://devfeed.tech/articles/revolut-phishing-texts-appear-days-after-data-breach-42143.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach>)

Author: Pieter Arntz

Published: 2026-09-17T14:07:15Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [breach](<https://devfeed.tech/tags/breach.md>), [password](<https://devfeed.tech/tags/password.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [revolut](<https://devfeed.tech/tags/revolut.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Revolut customers received phishing texts days after the bank disclosed customer data to a government impostor. The report says the campaign's connection to the breach is not yet known and describes a fake identity check designed to obtain passwords.

### Source excerpt

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

## Support the well-known change password URL with Appwrite Auth

DevFeed: [Support the well-known change password URL with Appwrite Auth](<https://devfeed.tech/articles/support-the-well-known-change-password-url-with-appwrite-auth-31444.md>)

Original publisher: [Read original article](<https://appwrite.io/blog/post/well-known-change-password-url>)

Author: Atharva Deosthale

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Appwrite Blog](<https://devfeed.tech/sources/appwrite-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Appwrite](<https://devfeed.tech/topics/appwrite.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [W3C](<https://devfeed.tech/topics/w3c.md>)

Tags: [bitwarden](<https://devfeed.tech/tags/bitwarden.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [tutorials](<https://devfeed.tech/tags/tutorials.md>), [w3c](<https://devfeed.tech/tags/w3c.md>)

### AI overview

This tutorial shows how to support the well-known change password URL in a TanStack Start app using Appwrite Auth. It explains the redirect, the change-password form for signed-out visitors, autocomplete hints, and deployment to Appwrite Sites.

### Source excerpt

Password managers open /.well-known/change-password when they find a leaked or weak password. Add the redirect and a change password page backed by Appwrite Auth.

## HBO Max's verified Reddit account hijacked to spread malware

DevFeed: [HBO Max's verified Reddit account hijacked to spread malware](<https://devfeed.tech/articles/hbo-max-s-verified-reddit-account-hijacked-to-spread-malware-26612.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware>)

Author: Pieter Arntz

Published: 2026-09-15T11:51:03Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [hbo-max](<https://devfeed.tech/tags/hbo-max.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pasteswitch](<https://devfeed.tech/tags/pasteswitch.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [reddit](<https://devfeed.tech/tags/reddit.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Cybercriminals hijacked HBO Max's verified Reddit account and used it to run 108 malicious ads over about 48 hours. The ads promoted fake software and used ClickFix-style instructions to distribute infostealers and cryptocurrency clipboard hijackers to macOS and Windows users.

### Source excerpt

Cybercriminals used HBO Max's verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

## UK.gov begins killing off passwords for 23 million users

DevFeed: [UK.gov begins killing off passwords for 23 million users](<https://devfeed.tech/articles/uk-gov-begins-killing-off-passwords-for-23-million-users-17411.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088>)

Author: Carly Page

Published: 2026-09-14T09:16:11Z

Content type: article

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [government-of-the-united-kingdom](<https://devfeed.tech/tags/government-of-the-united-kingdom.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>), [whitehall](<https://devfeed.tech/tags/whitehall.md>)

### AI overview

The UK government is beginning to replace passwords with passkeys for 23 million users. The change is intended to reduce phishing problems and save Whitehall approximately GBP 600 per day in SMS costs.

### Source excerpt

Passkeys promise fewer phishing headaches - and GBP 600 a day off Whitehall's SMS bill

## \[Crypto\] Time-based one-time password (TOTP) for 2FA, part II: YubiKey

DevFeed: [\[Crypto\] Time-based one-time password (TOTP) for 2FA, part II: YubiKey](<https://devfeed.tech/articles/crypto-time-based-one-time-password-totp-for-2fa-part-ii-yubikey-20551.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/TOTP2/>)

Published: 2026-09-13T22:00:00Z

Content type: article

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Code](<https://devfeed.tech/topics/code.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Android](<https://devfeed.tech/topics/android.md>), [USB](<https://devfeed.tech/topics/usb.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [linux](<https://devfeed.tech/tags/linux.md>), [password](<https://devfeed.tech/tags/password.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

The article examines using a YubiKey to store TOTP secrets for two-factor authentication. It explains that HMAC keys are intended to remain inside the device, but describes a Linux ykman weakness that could allow an attacker with temporary physical access to generate future TOTP keys and potentially log in during the relevant 30-second interval if the account password is also known.

### Source excerpt

[Crypto] Time-based one-time password (TOTP) for 2FA, part II: YubiKey

## \[Crypto\] Time-based one-time password (TOTP) for 2FA, part I

DevFeed: [\[Crypto\] Time-based one-time password (TOTP) for 2FA, part I](<https://devfeed.tech/articles/crypto-time-based-one-time-password-totp-for-2fa-part-i-20550.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/TOTP1/>)

Published: 2026-09-09T22:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [Google](<https://devfeed.tech/topics/google.md>), [Python](<https://devfeed.tech/topics/python.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [App](<https://devfeed.tech/topics/app.md>), [email](<https://devfeed.tech/topics/email.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [app](<https://devfeed.tech/tags/app.md>), [argument](<https://devfeed.tech/tags/argument.md>), [backup](<https://devfeed.tech/tags/backup.md>), [code](<https://devfeed.tech/tags/code.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [env-file-security](<https://devfeed.tech/tags/env-file-security.md>), [github](<https://devfeed.tech/tags/github.md>), [google](<https://devfeed.tech/tags/google.md>), [password](<https://devfeed.tech/tags/password.md>), [protection](<https://devfeed.tech/tags/protection.md>), [python](<https://devfeed.tech/tags/python.md>), [run](<https://devfeed.tech/tags/run.md>), [server](<https://devfeed.tech/tags/server.md>), [smartphone](<https://devfeed.tech/tags/smartphone.md>), [unix](<https://devfeed.tech/tags/unix.md>)

### AI overview

This tutorial explains how time-based one-time passwords work for two-factor authentication. It covers importing a base32-encoded secret from a QR code into Google Authenticator, generating 6-digit login codes, and calculating them with HMAC-SHA-1 from the secret and Unix time. It also discusses backup codes and securely storing TOTP secrets separately from passwords.

### Source excerpt

[Crypto] Time-based one-time password (TOTP) for 2FA, part I

## Accounts & Self-Service UX Research Update and Expansion: 3 Key Takeaways

DevFeed: [Accounts & Self-Service UX Research Update and Expansion: 3 Key Takeaways](<https://devfeed.tech/articles/accounts-self-service-ux-research-update-and-expansion-3-key-takeaways-9361.md>)

Original publisher: [Read original article](<https://feeds.baymard.com/link/9825/17443305/accounts-and-self-service-ux-research-2026>)

Author: Sally Collins

Published: 2026-09-09T08:05:00Z

Content type: article

Language: en

Sources: [Baymard Institute](<https://devfeed.tech/sources/baymard-institute.md>)

Topics: [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [insights](<https://devfeed.tech/tags/insights.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Baymard's updated Accounts & Self-Service UX research examines how ecommerce account experiences have changed since 2018. Based on more than 4,000 hours of research, 1,400 usability issues, and a survey of over 1,000 US adults, the article highlights account security and sign-in changes, including passkeys, one-time passcodes, and two-factor authentication.

### Source excerpt

(Note: Unfortunately, e-mail and RSS don't support advanced layouts and features. If the graphics in this article look strange, you may want to read the article in your web browser.) Key Takeaways Baymard has new research on Accounts & Self-Service UX The research uncovered UX issues and identified UX solutions specific to the Accounts area of ecommerce sites Much has changed in account security and sign in, order management and tracking, and order returns since our last large-scale research in 2018 Key Stats 4,000+ new hours of Accounts & Self-Service research 1,400+ usability issues observed in testing 1,000+ US adults surveyed as part of our complementary quantitative research Today at Baymard, we're announcing the launch of our new updated and expanded Accounts & Self-Service UX research. We first investigated UX issues in Accounts & Self-Service in 2018. In this update, we've retested all the UX issues observed in 2018, verified all our UX solutions, wrote new guidelines based on newly observed Accounts & Self-Service UX issues, and rewritten the bulk of our verified guidelines for improved usefulness and clarity. This work has resulted in 57 new and updated Accounts & Self-Service guidelines based on 1,400+ usability issues observed during testing. The 57 guidelines are a key foundation for ensuring a high-performing Accounts and Self-Service UX. Additionally, we've included mobile test observations for the first time. As a result, this study represents our most comprehensive findings on Accounts & Self Service ecommerce UX. In this article, we'll highlight 3 high-level insights from our new Accounts & Self-Service UX research findings. New Insights for Accounts & Self-Service UX Compared to 2018, the landscape of Accounts & Self-Service has changed dramatically, particularly in 3 areas. 1) Account Security and Sign In At J.Crew, participants updating their passwords were provided no guidance regarding the site's password requirements, and they were unable to

## Password Protection is now available per project on Pro

DevFeed: [Password Protection is now available per project on Pro](<https://devfeed.tech/articles/password-protection-is-now-available-per-project-on-pro-1041.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/password-protection-now-costs-20-per-project-per-month-on-pro>)

Author: Jas Garcha

Published: 2026-09-09T06:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [deployment](<https://devfeed.tech/tags/deployment.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Pro teams can enable Password Protection for individual projects for $20 per project per month, replacing the previous $150-per-month team-level add-on option.

### Source excerpt

Pro teams can now enable Password Protection for individual projects at $20 per project per month. When enabled, Password Protection requires visitors to enter a password you set before they can view the project's deployments. Open Security in the sidebar, select Deployment Protection, and turn it on. Disable it to stop future charges for that project. Previously, Password Protection was available only through a $150-per-month team-level add-on that covered every project. Learn more about Deployment Protection usage and pricing in the documentation. Read more

## MikroTik router flaws allow takeover without a password

DevFeed: [MikroTik router flaws allow takeover without a password](<https://devfeed.tech/articles/mikrotik-router-flaws-allow-takeover-without-a-password-8440.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/mikrotik-routers-can-be-taken-over-without-password>)

Author: Pieter Arntz

Published: 2026-09-08T09:49:16Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [cve-2026-67276](<https://devfeed.tech/tags/cve-2026-67276.md>), [cve-2026-86060](<https://devfeed.tech/tags/cve-2026-86060.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mikrotik](<https://devfeed.tech/tags/mikrotik.md>), [news](<https://devfeed.tech/tags/news.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Attackers are actively exploiting two MikroTik RouterOS flaws, dubbed MikroTrick, to bypass SSH authentication and escalate privileges on internet-exposed routers. The article recommends promptly installing RouterOS updates and restricting SSH and other remote-management access.

### Source excerpt

Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.

## Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

DevFeed: [Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)](<https://devfeed.tech/articles/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18-8443.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/podcast/2026/09/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18>)

Author: Malwarebytes Labs

Published: 2026-09-07T18:23:18Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [airline](<https://devfeed.tech/tags/airline.md>), [airline-miles](<https://devfeed.tech/tags/airline-miles.md>), [credit-card-points](<https://devfeed.tech/tags/credit-card-points.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [hotel-rewards](<https://devfeed.tech/tags/hotel-rewards.md>), [loyalty-account](<https://devfeed.tech/tags/loyalty-account.md>), [loyalty-points](<https://devfeed.tech/tags/loyalty-points.md>), [loyalty-points-fraud](<https://devfeed.tech/tags/loyalty-points-fraud.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [points](<https://devfeed.tech/tags/points.md>), [rewards-account](<https://devfeed.tech/tags/rewards-account.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>)

### AI overview

A Lock and Code podcast episode examines loyalty-points theft, why criminals target points balances, and ways companies and consumers can protect against fraud.

### Source excerpt

This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.

## X Money rollout linked to password-reset attacks

DevFeed: [X Money rollout linked to password-reset attacks](<https://devfeed.tech/articles/x-money-rollout-linked-to-password-reset-attacks-8449.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/scams/2026/09/x-money-rollout-linked-to-password-reset-attacks>)

Author: Pieter Arntz

Published: 2026-09-04T12:29:41Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [breach](<https://devfeed.tech/tags/breach.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [news](<https://devfeed.tech/tags/news.md>), [password-reset](<https://devfeed.tech/tags/password-reset.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [x-money](<https://devfeed.tech/tags/x-money.md>)

### AI overview

X is investigating unsolicited password-reset emails sent to users amid the wider availability of X Money. The company says it has found no evidence of a breach, successful account takeovers, or access to X Money funds.

### Source excerpt

As X expands into payments, users are receiving password-reset emails they didn't request. Here's what may be happening and how to stay safe.

## StreamRat Android malware spreads through Meta and TikTok ads

DevFeed: [StreamRat Android malware spreads through Meta and TikTok ads](<https://devfeed.tech/articles/streamrat-android-malware-spreads-through-meta-and-tiktok-ads-8441.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads>)

Author: Pieter Arntz

Published: 2026-09-03T16:04:24Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [advertising](<https://devfeed.tech/tags/advertising.md>), [android](<https://devfeed.tech/tags/android.md>), [browser](<https://devfeed.tech/tags/browser.md>), [malware](<https://devfeed.tech/tags/malware.md>), [meta](<https://devfeed.tech/tags/meta.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [streamrat](<https://devfeed.tech/tags/streamrat.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [tiktok](<https://devfeed.tech/tags/tiktok.md>)

### AI overview

A malicious ad campaign used fake streaming-service promotions on Meta and TikTok to distribute the StreamRat Android banking Trojan. The campaign directed Android users to a tailored download page that coached them past security warnings and enabled credential theft and remote device control.

### Source excerpt

Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

## Introducing universal sign-in: a seamless solution for every way you login

DevFeed: [Introducing universal sign-in: a seamless solution for every way you login](<https://devfeed.tech/articles/introducing-universal-sign-in-a-seamless-solution-for-every-way-you-login-1935.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-universal-sign-in>)

Author: info@1password.com (Travis Hogan and Brandon Lucier)

Published: 2026-09-03T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [1password-in-the-browser](<https://devfeed.tech/tags/1password-in-the-browser.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extension](<https://devfeed.tech/tags/extension.md>), [launch](<https://devfeed.tech/tags/launch.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password releases universal sign-in in its browser extension, presenting passwords, passkeys, one-time codes, social logins, and managed-app methods in one prompt.

### Source excerpt

Today we're releasing universal sign-in, a new experience from 1Password that provides a seamless and secure way to sign into any site with your preferred method. It's currently available to all customers in the latest version of the 1Password browser extension. A single prompt for every sign-in Signing in doesn't happen one way anymore. A single site might support passwords, passkeys, or third-party providers like Google. Over the last several years, 1Password has evolved to support all major authentication methods used today (passwords, passkeys, 2FA, social logins, OIDC and SAML). But the authentication experience varied because of differences with the underlying technologies. Not having a consistent way to use every authentication type 1Password offered meant needing to remember which third-party provider account you used, manually submitting pages, or needing to find and click sign-in fields. No password manager on the market had a single, consistent way to let you sign in, until now. Universal sign-in means that when you land on a login page, 1Password displays a single prompt to sign in using the authentication method you've chosen for that website. No need to remember how you've logged into the website in the past; passwords, passkeys, one-time codes, social logins, and company-managed apps will all appear in the same, intuitive prompt. Simply pick which account you'd like to sign in with, and 1Password handles the rest. How it works Visit a login page, or launch a saved login in 1Password with an available sign-in URL. The universal sign-in prompt appears at the top of the login page using our new advanced field analysis. It'll appear when you need it, and disappear when you don't. Every account and available authentication method is listed and selectable within the universal sign-in prompt. Choose the login you'd like to use. Over time, 1Password also learns which accounts and methods you prefer using for that site. 1Password then automatically fills your

## Provision a secure Amazon DocumentDB cluster with Terraform

DevFeed: [Provision a secure Amazon DocumentDB cluster with Terraform](<https://devfeed.tech/articles/provision-a-secure-amazon-documentdb-cluster-with-terraform-4707.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/database/provision-a-secure-amazon-documentdb-cluster-with-terraform/>)

Author: Sourav Kundu

Published: 2026-08-31T20:24:23Z

Content type: tutorial

Language: en

Sources: [AWS Database Blog](<https://devfeed.tech/sources/aws-database-blog.md>)

Topics: [Amazon DocumentDB](<https://devfeed.tech/topics/amazon-documentdb.md>), [iac-security](<https://devfeed.tech/topics/iac-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [amazon-cloudwatch](<https://devfeed.tech/tags/amazon-cloudwatch.md>), [amazon-documentdb](<https://devfeed.tech/tags/amazon-documentdb.md>), [amazon-vpc](<https://devfeed.tech/tags/amazon-vpc.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [technical-how-to](<https://devfeed.tech/tags/technical-how-to.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

A walkthrough for provisioning a secure Amazon DocumentDB 8.0 cluster with Terraform. It applies infrastructure-as-code security controls including private VPC subnets, TLS, KMS encryption, secrets-managed passwords, security groups, and encrypted monitoring logs.

### Source excerpt

Learn how to provision a secure Amazon DocumentDB cluster using Terraform. This post applies infrastructure-as-code best practices with encryption, AWS Secrets Manager authentication, network isolation, and encrypted monitoring.

## Password spraying campaign targets AWS root user accounts across 150+ organizations

DevFeed: [Password spraying campaign targets AWS root user accounts across 150+ organizations](<https://devfeed.tech/articles/password-spraying-campaign-targets-aws-root-user-accounts-across-150-organizations-8272.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/>)

Author: Martin McCloskey

Published: 2026-08-31T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [password-spraying](<https://devfeed.tech/tags/password-spraying.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Datadog Security Research describes a password spraying campaign that repeatedly targeted AWS root user accounts at more than 150 organizations between July 24 and August 23, 2026. The campaign used Chrome and Firefox user-agent fingerprints and proxy infrastructure; no successful authentications were observed, and the attackers' motive remains undetermined. The article explains the privileges and safeguards associated with AWS root users and recommends reducing reliance on persistent root credentials.

### Source excerpt

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

## From one switch to a control panel: meet \`dataCollection\`

DevFeed: [From one switch to a control panel: meet \`dataCollection\`](<https://devfeed.tech/articles/from-one-switch-to-a-control-panel-meet-datacollection-24094.md>)

Original publisher: [Read original article](<https://blog.sentry.io/datacollection-control-panel/>)

Author: Sigrid Huemer

Published: 2026-08-28T09:00:00Z

Content type: release

Language: en

Sources: [Sentry Blog](<https://devfeed.tech/sources/sentry-blog.md>)

Topics: [SDKs](<https://devfeed.tech/topics/sdks.md>), [data](<https://devfeed.tech/topics/data.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [api-keys](<https://devfeed.tech/tags/api-keys.md>), [data](<https://devfeed.tech/tags/data.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [release-notes](<https://devfeed.tech/tags/release-notes.md>), [sdks](<https://devfeed.tech/tags/sdks.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

Sentry is replacing the all-or-nothing `sendDefaultPii` setting with `dataCollection`, which provides granular control over automatically collected data such as user information, headers, request bodies, and GenAI data. The change is rolling out across Sentry SDKs, with JavaScript SDK v11 making it the default and collecting more data than v10 by default.

### Source excerpt

Sentry SDKs replace the `sendDefaultPii` boolean with `dataCollection`, granular options for user data, headers, bodies, GenAI data, and more.

## 1Password product enhancements: Smarter autofill, phishing prevention, and more

DevFeed: [1Password product enhancements: Smarter autofill, phishing prevention, and more](<https://devfeed.tech/articles/1password-product-enhancements-smarter-autofill-phishing-prevention-and-more-1884.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-product-enhancements-smarter-autofill-phishing-prevention>)

Author: info@1password.com (Elaine Atwell)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [iphone](<https://devfeed.tech/topics/iphone.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ios](<https://devfeed.tech/tags/ios.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [macos](<https://devfeed.tech/tags/macos.md>), [migration](<https://devfeed.tech/tags/migration.md>), [news](<https://devfeed.tech/tags/news.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [product](<https://devfeed.tech/tags/product.md>), [saas](<https://devfeed.tech/tags/saas.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This English developer article presents recent 1Password product enhancements focused on smoother credential management and sign-in. It covers universal sign-in for personal and business accounts, macOS autofill, native password generation and saving in iOS 26.2, an iOS autofill health check, and improvements related to data ownership and migration.

### Source excerpt

At 1Password, we're constantly working to make life simpler and more secure for our users, from the biggest businesses to each individual who signs up for our password manager. Over the past few months, we've been rolling out a slew of updates designed to make a difference for customers, whether you're using us at home, at work, or (ideally) both. Here are some of the latest developments for you to explore. Upgrades to autofill and autosave One of the most immediate benefits of using 1Password in your daily life is a smooth experience of creating, saving, and inputting your credentials and logins. These updates help you get the most out of that experience, with fewer clicks, on the devices you already use. Universal sign-in for personal and business accounts Signing in just got simpler with a smarter, modern experience using a one-click prompt. Now in beta, 1Password seamlessly logs you into any site or service at the right moment using your desired authentication method (passwords, passkeys, social sign in, OIDC, SAML*). We remove all the extra steps so you sign in quickly and smoothly, while staying secure. *SAML is only available for business accounts that also have 1Password SaaS Manager. macOS autofill 1Password now works as a native Credential Provider on macOS, so your logins and passkeys easily fill right inside Safari and other desktop apps. Save and generate passwords in iOS 26.2 The password creation experience on iPhone and iPad should happen at the exact moment you need it, especially when you're signing up for a new account. With this update, 1Password shows up natively in Safari and other iOS-native apps so you can generate and save a strong password right in the account creation flow, without leaving what you're doing. This makes it easier to capture credentials when they're created and keeps account setup uninterrupted. Autofill health check for iOS The reliability of iOS autofill depends on a tangle of systems, and when there's a problem with one,

## How to migrate from a custom auth system to a third-party provider

DevFeed: [How to migrate from a custom auth system to a third-party provider](<https://devfeed.tech/articles/how-to-migrate-from-a-custom-auth-system-to-a-third-party-provider-16032.md>)

Original publisher: [Read original article](<https://workos.com/blog/migrate-custom-auth-to-third-party-provider>)

Author: WorkOS

Published: 2026-08-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [migration](<https://devfeed.tech/topics/migration.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [migration](<https://devfeed.tech/tags/migration.md>), [password](<https://devfeed.tech/tags/password.md>), [rollback](<https://devfeed.tech/tags/rollback.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [third-party](<https://devfeed.tech/tags/third-party.md>)

### AI overview

A guide to moving from a custom authentication system to a third-party provider. It explains how password-hash portability, SSO callback control, and an inventory of existing authentication components determine the migration strategy and cutover plan.

### Source excerpt

What is actually portable, how to import password hashes without forcing a reset, and how to cut over with a rollback you can trust.

## Environment variables now use Config and Secret types

DevFeed: [Environment variables now use Config and Secret types](<https://devfeed.tech/articles/environment-variables-now-use-config-and-secret-types-917.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/environment-variables-now-use-config-and-secret-types>)

Author: Brooke Mosby

Published: 2026-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [configuration](<https://devfeed.tech/topics/configuration.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [config](<https://devfeed.tech/tags/config.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel now uses Config and Secret types for environment variables instead of the Sensitive toggle. Config values remain readable to authorized members, while Secret values remain available to deployments but cannot be viewed or retrieved after saving. The update also introduces a policy for separating Production secret values and adds CLI support through visibility settings.

### Source excerpt

When you add or edit an environment variable in Vercel, you now choose Config or Secret instead of using the Sensitive toggle. Existing variables marked Sensitive are automatically treated as Secrets and continue to work without migration. Config: The value remains readable after saving for members with access. Use Config for non-sensitive values you may need to inspect later, such as variables with a public framework prefix. Secret: The value remains available to your deployments and can be replaced, but members cannot view or retrieve it after saving. Use Secret for passwords, API keys, and tokens. You can select an environment or Preview branch for each value. The environment variable list in the dashboard shows each variable's type and where it applies. Team policy changes The Enforce Sensitive Environment Variables team policy is deprecated with this update. When enabled, it required every environment variable created by a team member to be Sensitive, including non-sensitive configuration. With Config and Secret types, members can choose the appropriate type for each variable. A new Separate Production Secret Values policy is available in your Security settings. When enabled, the Production value for a Secret must differ from the values used for the same key in Preview, Development, and custom environments. If your team had the legacy policy enabled, confirm whether the Separate Production Secret Values policy should be enabled for your team. The deprecated policy is no longer enforced by the Vercel CLI. Set variable types from the CLI To choose whether an environment variable is a Config or Secret from the CLI, pass --visibility config or --visibility secret to vercel env add or vercel env update: The existing flags continue to work. When --visibility is omitted, --no-sensitive maps to Config and --sensitive maps to Secret. After adding or updating a variable, the CLI output shows its type under Visibility. Learn more in the Environment Variables documentation

## Advisory Solutions reaches 1Password Certified Partner status

DevFeed: [Advisory Solutions reaches 1Password Certified Partner status](<https://devfeed.tech/articles/advisory-solutions-reaches-1password-certified-partner-status-1890.md>)

Original publisher: [Read original article](<https://1password.com/blog/advisory-solutions-reaches-certified-partner-status>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-08-17T00:00:00Z

Content type: news

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [partners](<https://devfeed.tech/tags/partners.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Advisory Solutions reached Certified Tier status in the 1Password Partner program after scaling its 1Password deployment to more than 1,000 managed users.

### Source excerpt

The launch of 1Password Enterprise Password Manager - MSP Edition marked a critical step in 1Password's mission to support our Managed Service Provider (MSP) partnerships. Now, we are pleased to announce that Advisory Solutions, a New York City-based MSP that works with companies worldwide, has reached the Certified Tier in the 1Password Partner program. 1Password's new Certified tier is a milestone we've implemented to recognize the investment and success of MSP partners who have reached 1,000 or more managed external users. Advisory Solutions was able to become a Certified Partner by rapidly scaling its 1Password deployment to more than 1,000 managed users. This not only represents their dedication as a partner, but demonstrates that the Certified tier is an achievable milestone for MSPs committed to growing their 1Password practice. We're excited to see companies like Advisory Solutions further the momentum behind 1Password's MSP program and embrace the value of participating in it. The journey to Certified Partner for 1Password MSPs What does it take for an MSP to work their way up from Authorized to the Certified Tier? Jay Chaudhrey, Director of Business Development at Advisory Solutions, shares some of the key principles that Advisory Solutions followed to operationalize 1Password and become a Certified Partner so rapidly. Authorized and Certified Partners 1Password's MSP Partner Program now consists of two tiers: Authorized and Certified. Like every MSP in 1Password's program, Advisory Solutions began as an Authorized Partner, establishing the operational foundation that ultimately led to the becoming a Certified Partner. At the Authorized Tier, partners gain immediate benefits, including specialized pricing NFR licenses for internal use, and enablement resources. For Advisory Solutions, "It was really important for us to work with the best companies in their respective fields." That's how they found 1Password. When it comes to finding the "best" tools, Chaud

## 1Password's back-to-school tips for the digital world

DevFeed: [1Password's back-to-school tips for the digital world](<https://devfeed.tech/articles/1password-s-back-to-school-tips-for-the-digital-world-1922.md>)

Original publisher: [Read original article](<https://1password.com/blog/getting-started-students-and-families>)

Author: info@1password.com (1Password)

Published: 2026-08-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Digital Security](<https://devfeed.tech/topics/digital-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [claude](<https://devfeed.tech/tags/claude.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [guide](<https://devfeed.tech/tags/guide.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [tips-advice](<https://devfeed.tech/tags/tips-advice.md>)

### AI overview

1Password's back-to-school guide offers parents and students practical advice for staying secure and organized in the digital world. It focuses on evaluating AI tools, protecting personal information and passwords, avoiding phishing and password reuse, and building safer online habits.

### Source excerpt

It happened again. We blinked, and suddenly summer's over and it's time to register for classes. The horror! While the start of a new school year has always been a stressful time for parents and students, the growing number of accounts, apps, and devices students have been responsible for in recent years has made it even more complicated. To help manage the stress, 1Password is sharing our favorite back-to-school security tips for parents and students of all ages, so you can start the 2026 school year secure and organized. School security 101: From AI to user IDs With more AI tools emerging every day, it can be difficult to track which ones are trustworthy. AI tools and agents need access to a lot of data in order to function; AI adopters, and concerned parents, should take care about what data is being shared with the AI. It's worth learning what AI-based tools your kids are using, and educating them about what kinds of information they should never share with a chatbot. That includes sensitive personal information, but it also includes things like passwords, which no AI user should paste directly into a chat window just because a helpful-seeming agent asked for them. Tools like 1Password for Claude offer a safe way for the AI power users in your family to experiment with agents. For any parents, whether your kids are entering elementary school or going off to college for the first time, they can benefit from a talk about AI tools and online safety. You don't have to scare your kids away from technology, nor should you try to control everything they do online. Instead, set them up for success with knowledge and preparation. 💡Heading to college or university? Check out our blog, A college student's guide to better digital security. Make strong passwords a habit now Despite the perception that young people today are tech-savvy, that doesn't mean they're secure. With apps for school, home, and socializing, the average student is creating more accounts than they can po

## Yet another password manager: pass with Pass for iOS

DevFeed: [Yet another password manager: pass with Pass for iOS](<https://devfeed.tech/articles/yet-another-password-manager-pass-with-pass-for-ios-41909.md>)

Original publisher: [Read original article](<https://jpmens.net/2026/08/11/yet-another-password-manager/>)

Author: Jan-Piet Mens

Published: 2026-08-10T22:00:00Z

Content type: opinion

Language: en

Sources: [Jan-Piet Mens](<https://devfeed.tech/sources/jan-piet-mens.md>)

Topics: [pass](<https://devfeed.tech/topics/password-store.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>), [Git](<https://devfeed.tech/topics/git.md>), [forgejo](<https://devfeed.tech/topics/forgejo.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [forgejo](<https://devfeed.tech/tags/forgejo.md>), [git](<https://devfeed.tech/tags/git.md>), [ios](<https://devfeed.tech/tags/ios.md>), [jan-piet-mens](<https://devfeed.tech/tags/jan-piet-mens.md>), [jpm](<https://devfeed.tech/tags/jpm.md>), [jpmens](<https://devfeed.tech/tags/jpmens.md>), [pass](<https://devfeed.tech/tags/pass.md>), [password](<https://devfeed.tech/tags/password.md>), [password-manager](<https://devfeed.tech/tags/password-manager.md>), [terminal](<https://devfeed.tech/tags/terminal.md>)

### AI overview

A personal review of pass, the standard Unix password manager, and Pass for iOS. The article describes pass's GPG-encrypted file-based store, optional Git-based synchronization, terminal workflow, and relevance to Ansible password lookups.

### Source excerpt

I remember the good times, when I had a single password for all (the two?) services I used. Then came a phase of managing passwords on sticky notes stuck below the keyboard (much more secure than stuck to the monitor!), until I migrated to one of the first note-taking apps and had passwords written in clear like on the sticky notes but copy/pasteable. Those were the days! Then came the first "real" password manager which for me was 1Password. It worked, I synced with a local store (i.e. sans Internet) until the company decided to convert my "paid for life" (which never exists) into a subscription model. I spent days thinking and rethinking and settled for Enpass which I've used since on macOS and iOS. It's okay, and does what I want from it, but its enshitification is in progress. There are others, lots of others, and I looked closely at KeePassXC, but can't seem to make the jump. One of the password managers I kept an eye upon for a while was pass, a.k.a. passwordstore. It must have been a dozen years ago that I fell for the cool little tool which lives in my terminal, but as there wasn't an iOS pendant, I kept pushing it aside. Interestingly, for years now, I've mentioned it in my Ansible trainings when I very briefly explain the passwordstore lookup plugin when going through a short list of lookups. Moving forward, I stumbled across a program which piqued my interest yesterday: Pass for iOS, and decided to take a closer look to see whether the combination of that plus pass might tickle me again. pass the standard unix password manager pass calls itself the standard unix password manager, and with that it is in line with ed, the standard unix text editor. Both have no frills and no AI. In pass individual passwords live in gpg-encrypted files whose name is the title of the site or resource the password is for. These files can be organized into hierarchies, for instance: $ pass Password Store ├── ansible │ └── vaultsecret ├── jpmens │ └── org │ └── repo └── testing

## CSS:the bomb inside your inbox

DevFeed: [CSS:the bomb inside your inbox](<https://devfeed.tech/articles/css-the-bomb-inside-your-inbox-7674.md>)

Original publisher: [Read original article](<https://portswigger.net/research/css-the-bomb-inside-your-inbox>)

Author: Gareth Heyes

Published: 2026-08-06T22:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [modern web development](<https://devfeed.tech/topics/modern-web-development.md>), [Web Development](<https://devfeed.tech/topics/web-development.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [atlas](<https://devfeed.tech/tags/atlas.md>), [browser](<https://devfeed.tech/tags/browser.md>), [bug](<https://devfeed.tech/tags/bug.md>), [css](<https://devfeed.tech/tags/css.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [html](<https://devfeed.tech/tags/html.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [ui](<https://devfeed.tech/tags/ui.md>)

### AI overview

A security paper on abusing discrepancies between CSS/HTML sanitizers and browser rendering in webmail clients. It describes techniques that can cross trust boundaries, spoof UI actions, exfiltrate tokens, and steal passwords, including an Outlook UI-control issue involving HTML labels.

### Source excerpt

Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this

## Linux ssh-keygen: Set Up SSH Key Authentication the Right Way

DevFeed: [Linux ssh-keygen: Set Up SSH Key Authentication the Right Way](<https://devfeed.tech/articles/linux-ssh-keygen-set-up-ssh-key-authentication-the-right-way-20873.md>)

Original publisher: [Read original article](<https://linuxblog.io/linux-ssh-keygen-set-up-ssh-key-authentication-the-right-way/>)

Author: Hayden James

Published: 2026-08-03T10:53:19Z

Content type: tutorial

Language: en

Sources: [Hayden James](<https://devfeed.tech/sources/hayden-james.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [blog](<https://devfeed.tech/tags/blog.md>), [guide](<https://devfeed.tech/tags/guide.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [password](<https://devfeed.tech/tags/password.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sysadmins](<https://devfeed.tech/tags/sysadmins.md>)

### AI overview

A practical guide to setting up SSH key authentication on Linux with ssh-keygen. It covers generating key pairs, copying public keys to servers, disabling password login safely, configuring multiple identities, and using passphrases or FIDO2 security keys.

### Source excerpt

Password-based SSH login is a liability. This guide walks through generating SSH key pairs with ssh-keygen, deploying public keys, disabling password authentication, and managing multiple keys cleanly with ~/.ssh/config. Continue reading...

[Next page](<https://devfeed.tech/topics/passwords.md?cursor=WyIyMDI2LTA4LTAzVDEwOjUzOjE5KzAwOjAwIiwgIjQ4YWRhMjJmLWNhYWEtNDM0My1iZTJiLTg3OTI4NTc0MDZiYSJd>)