<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: A</title>
    <description>The latest articles on DEV Community by A (@antonmb).</description>
    <link>https://dev.to/antonmb</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3667847%2F5517e5b7-498d-45aa-995d-6628e9d67176.jpeg</url>
      <title>DEV Community: A</title>
      <link>https://dev.to/antonmb</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/antonmb"/>
    <language>en</language>
    <item>
      <title>I am currently open to new opportunities and collaboration</title>
      <dc:creator>A</dc:creator>
      <pubDate>Tue, 28 Apr 2026 21:55:35 +0000</pubDate>
      <link>https://dev.to/antonmb/i-am-currently-open-to-new-opportunities-and-collaboration-576a</link>
      <guid>https://dev.to/antonmb/i-am-currently-open-to-new-opportunities-and-collaboration-576a</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/antonmb/open-to-work-and-collaboration-3l23" class="crayons-story__hidden-navigation-link"&gt;Open to Work and Collaboration&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/antonmb" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3667847%2F5517e5b7-498d-45aa-995d-6628e9d67176.jpeg" alt="antonmb profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/antonmb" class="crayons-story__secondary fw-medium m:hidden"&gt;
              A
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                A
                
              
              &lt;div id="story-author-preview-content-3559918" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/antonmb" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3667847%2F5517e5b7-498d-45aa-995d-6628e9d67176.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;A&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/antonmb/open-to-work-and-collaboration-3l23" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Apr 28&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/antonmb/open-to-work-and-collaboration-3l23" id="article-link-3559918"&gt;
          Open to Work and Collaboration
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/career"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;career&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/softwareengineering"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;softwareengineering&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/programming"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;programming&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/antonmb/open-to-work-and-collaboration-3l23" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;5&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/antonmb/open-to-work-and-collaboration-3l23#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            1 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Why access-first auth matters?</title>
      <dc:creator>A</dc:creator>
      <pubDate>Fri, 24 Apr 2026 11:01:05 +0000</pubDate>
      <link>https://dev.to/antonmb/why-access-first-auth-matters-pm5</link>
      <guid>https://dev.to/antonmb/why-access-first-auth-matters-pm5</guid>
      <description>&lt;p&gt;In this article, I briefly explain why Toqen.app is built around an access-first authentication infrastructure.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Where fast access matters
&lt;/h2&gt;

&lt;p&gt;There are scenarios where filling out forms gets in the way:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;one-time website visits
&lt;/li&gt;
&lt;li&gt;Smart TVs
&lt;/li&gt;
&lt;li&gt;events and webinars
&lt;/li&gt;
&lt;li&gt;admin panels and systems where ownership must be confirmed frequently
&lt;/li&gt;
&lt;li&gt;systems where services, agents, or bots interact with each other
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In these cases, email and passwords slow things down and increase risk.&lt;/p&gt;

&lt;p&gt;Toqen.app provides access instantly through confirmation, without entering unnecessary data.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Access without unnecessary data
&lt;/h2&gt;

&lt;p&gt;Instead of creating and managing accounts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;open the website
&lt;/li&gt;
&lt;li&gt;scan a QR code
&lt;/li&gt;
&lt;li&gt;confirm access
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Access is confirmed at the moment of request, not stored in advance.&lt;/p&gt;

&lt;p&gt;It does not matter where you are or what device you use everything happens in just a few steps.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Access control at the moment of use
&lt;/h2&gt;

&lt;p&gt;With Toqen.app, every access can be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;confirmed
&lt;/li&gt;
&lt;li&gt;restricted
&lt;/li&gt;
&lt;li&gt;revoked
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This gives control not only at login, but during actual usage.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Simple and predictable security
&lt;/h2&gt;

&lt;p&gt;Most authentication issues come from human error:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;forgotten passwords
&lt;/li&gt;
&lt;li&gt;password reuse
&lt;/li&gt;
&lt;li&gt;phishing
&lt;/li&gt;
&lt;li&gt;input mistakes
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With Toqen.app:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;no passwords to enter
&lt;/li&gt;
&lt;li&gt;no unnecessary steps
&lt;/li&gt;
&lt;li&gt;every access is confirmed on your device
&lt;/li&gt;
&lt;li&gt;device-bound cryptographic keys are used
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This reduces mistakes and makes the process predictable.&lt;/p&gt;

&lt;p&gt;Even in stressful situations, there is only one action confirm access.&lt;/p&gt;

&lt;p&gt;It follows modern approaches similar to WebAuth, with a more straightforward user experience.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Less data, lower risk
&lt;/h2&gt;

&lt;p&gt;Traditional systems store:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;emails
&lt;/li&gt;
&lt;li&gt;passwords
&lt;/li&gt;
&lt;li&gt;tokens
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;With Toqen.app:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;only data required for access is used
&lt;/li&gt;
&lt;li&gt;no unnecessary personal information is stored
&lt;/li&gt;
&lt;li&gt;each access request is single-use
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This reduces the impact of mistakes and data leaks.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. Simple and fast integration
&lt;/h2&gt;

&lt;p&gt;For developers, speed of integration matters as much as security.&lt;/p&gt;

&lt;p&gt;Toqen.app:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;does not require complex setup
&lt;/li&gt;
&lt;li&gt;does not require identity-centric user profiles
&lt;/li&gt;
&lt;li&gt;allows collecting data required by business logic
&lt;/li&gt;
&lt;li&gt;integrates as an access layer on top of existing systems
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This makes it possible to introduce secure access without redesigning the architecture.&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary
&lt;/h2&gt;

&lt;p&gt;Toqen.app is an approach where:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;access is confirmed in real time
&lt;/li&gt;
&lt;li&gt;unnecessary data is not required
&lt;/li&gt;
&lt;li&gt;users stay in control
&lt;/li&gt;
&lt;li&gt;the system remains simple and clear
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You do not remember access you confirm it when you need it.&lt;/p&gt;

&lt;h2&gt;
  
  
  P.S.
&lt;/h2&gt;

&lt;p&gt;The app is available on the App Store. Closed testing on Google Play is ongoing message me if you want to try it.&lt;/p&gt;

&lt;p&gt;The client app is open source, so you can review how access confirmation works and what data is actually used: &lt;a href="https://github.com/toqenapp/mobile-react-native" rel="noopener noreferrer"&gt;https://github.com/toqenapp/mobile-react-native&lt;/a&gt;&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>authentication</category>
      <category>cybersecurity</category>
      <category>architecture</category>
    </item>
    <item>
      <title>Forgot your password again? QR Man is here to help.</title>
      <dc:creator>A</dc:creator>
      <pubDate>Wed, 22 Apr 2026 13:14:31 +0000</pubDate>
      <link>https://dev.to/antonmb/forgot-your-password-again-qr-man-is-here-to-help-3pbi</link>
      <guid>https://dev.to/antonmb/forgot-your-password-again-qr-man-is-here-to-help-3pbi</guid>
      <description>&lt;p&gt;&lt;strong&gt;Friend:&lt;/strong&gt; "So, what’s this Toqen.app thing anyway? Just another password manager? I have everything saved in my browser, I’m good."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; "That’s the thing - it’s not. Browsers remember your passwords. Toqen.app makes them unnecessary."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Friend:&lt;/strong&gt; "What do you mean 'unnecessary'? How am I supposed to log in? Magic?"&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; "Think of it this way: a standard login is like a door with a cheap lock. Anyone with a copy of the key-your password-can walk right in. Toqen.app turns your smartphone into a universal digital key. You don’t have to type anything. You just walk up to the 'door' (open the website), scan a QR code, and your phone tells the site: 'Everything’s good, this is the owner, let him in.'"&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Friend:&lt;/strong&gt; "Wait, so I don’t have to remember anything? That sounds like a security nightmare. Okay, what if I’m sitting in a cafe and someone else tries to log in using my name from the other side of the world?"&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; "That’s the main 'wow' effect. An attacker gets nowhere because there are no reusable credentials on the server. Unlike a password, which can be stolen and used again, the server only holds your public key. To log in, your phone creates a unique device signature for that specific moment. The server only verifies the signature - it never sees or stores your actual 'secret.' Even if someone intercepted the data, they couldn't use it to log in later. Your 'master key' stays physically on your phone and nowhere else."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Friend:&lt;/strong&gt; "Right, but what if I lose my phone? Or worse, what if it gets stolen?"&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; "That’s the key part. It’s like the keys to a modern car: no one else can even start the 'engine' without your specific biometrics. If you lose it, you restore access via a backup. It’s stored in an encrypted format that is mathematically impractical to crack without your master key. Meanwhile, your lost device remains useless to an intruder because it's protected by multiple layers of hardware-level security."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Friend:&lt;/strong&gt; "So... it’s basically like FaceID for the entire internet?"&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Me:&lt;/strong&gt; "Exactly. It makes your digital life seamless. You move through websites like you’re walking through your own home, where all the doors open automatically as you approach. No stress, just access."&lt;/p&gt;

</description>
      <category>security</category>
      <category>passwordless</category>
      <category>authentication</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Toqen.app Mobile is Now Open Source</title>
      <dc:creator>A</dc:creator>
      <pubDate>Wed, 22 Apr 2026 03:29:35 +0000</pubDate>
      <link>https://dev.to/antonmb/toqenapp-mobile-is-now-open-source-4o78</link>
      <guid>https://dev.to/antonmb/toqenapp-mobile-is-now-open-source-4o78</guid>
      <description>&lt;p&gt;I have made the Toqen.app mobile application publicly available.&lt;/p&gt;

&lt;p&gt;This is a deliberate decision to move toward transparency and independent technical review.&lt;/p&gt;

&lt;p&gt;The mobile client is the part of the system that users directly interact with during authorization.&lt;br&gt;&lt;br&gt;
It is now open for inspection so anyone can verify how access is processed on the device.&lt;/p&gt;




&lt;h2&gt;
  
  
  What is Toqen
&lt;/h2&gt;

&lt;p&gt;Toqen is an access-first authentication infrastructure designed for secure, real-time authorization.&lt;/p&gt;

&lt;p&gt;Each access request is:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;created in real time
&lt;/li&gt;
&lt;li&gt;explicitly approved by the user
&lt;/li&gt;
&lt;li&gt;cryptographically signed by the device
&lt;/li&gt;
&lt;li&gt;verified by the backend
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The mobile app acts as a secure execution layer for these decisions.&lt;/p&gt;




&lt;h2&gt;
  
  
  What the open source mobile app actually does
&lt;/h2&gt;

&lt;p&gt;The mobile client has a very narrow and well-defined responsibility:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;scan or receive an access request
&lt;/li&gt;
&lt;li&gt;fetch request context from the backend
&lt;/li&gt;
&lt;li&gt;show the user what is being requested
&lt;/li&gt;
&lt;li&gt;collect explicit approval or denial
&lt;/li&gt;
&lt;li&gt;sign a short-lived challenge using a device key
&lt;/li&gt;
&lt;li&gt;send the signed result back for verification
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The app does not grant access on its own.&lt;br&gt;&lt;br&gt;
All final decisions are verified by the server.&lt;/p&gt;




&lt;h2&gt;
  
  
  What data the app collects
&lt;/h2&gt;

&lt;p&gt;This is the key point.&lt;/p&gt;

&lt;p&gt;You can verify it directly in the code.&lt;/p&gt;

&lt;p&gt;The mobile app stores only what is strictly required to perform cryptographic authorization:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;device_private_key&lt;/code&gt; (generated on device, never leaves it)
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;device_id&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;app_instance_id&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;That is the full set of stored sensitive data.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;There is no storage of:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;passwords
&lt;/li&gt;
&lt;li&gt;session tokens
&lt;/li&gt;
&lt;li&gt;refresh tokens
&lt;/li&gt;
&lt;li&gt;reusable credentials
&lt;/li&gt;
&lt;li&gt;backend secrets
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Sensitive data is stored using OS-level secure storage (Keychain / Keystore).&lt;/p&gt;




&lt;h2&gt;
  
  
  What is NOT inside the system
&lt;/h2&gt;

&lt;p&gt;Toqen is built around strict data minimization.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;QR codes do not contain secrets
&lt;/li&gt;
&lt;li&gt;authorization requests are short-lived
&lt;/li&gt;
&lt;li&gt;requests are single-use
&lt;/li&gt;
&lt;li&gt;no reusable tokens exist in the flow
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Even if a QR code is intercepted, it cannot be used to gain access.&lt;/p&gt;

&lt;p&gt;Authorization always requires:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;user confirmation
&lt;/li&gt;
&lt;li&gt;device signature
&lt;/li&gt;
&lt;li&gt;backend verification
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  How authorization actually works
&lt;/h2&gt;

&lt;p&gt;All flows follow the same pattern:&lt;br&gt;
request → context → user decision → signature → verification → result&lt;/p&gt;

&lt;p&gt;This guarantees:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;no silent approvals
&lt;/li&gt;
&lt;li&gt;no implicit trust
&lt;/li&gt;
&lt;li&gt;no background authorization
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every access is intentional and verifiable.&lt;/p&gt;




&lt;h2&gt;
  
  
  Security model (short version)
&lt;/h2&gt;

&lt;p&gt;The system assumes a hostile environment:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;network is untrusted
&lt;/li&gt;
&lt;li&gt;QR codes can be intercepted
&lt;/li&gt;
&lt;li&gt;requests can be replayed
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Security is achieved through:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;device-bound cryptographic keys
&lt;/li&gt;
&lt;li&gt;challenge-response authorization
&lt;/li&gt;
&lt;li&gt;short-lived requests
&lt;/li&gt;
&lt;li&gt;server-side verification
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Private keys never leave the device.&lt;br&gt;&lt;br&gt;
The backend never has access to them.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why only the mobile app is open
&lt;/h2&gt;

&lt;p&gt;The mobile client is the most critical part to verify from a trust perspective.&lt;/p&gt;

&lt;p&gt;By open-sourcing it, I allow:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;independent security review
&lt;/li&gt;
&lt;li&gt;verification of data handling
&lt;/li&gt;
&lt;li&gt;inspection of cryptographic flows
&lt;/li&gt;
&lt;li&gt;validation of what is and is not collected
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The backend remains closed, but its behavior is fully defined through:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;API contracts
&lt;/li&gt;
&lt;li&gt;documented flows
&lt;/li&gt;
&lt;li&gt;security model
&lt;/li&gt;
&lt;li&gt;threat model
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This keeps the system verifiable without exposing operational infrastructure.&lt;/p&gt;




&lt;h2&gt;
  
  
  Build transparency
&lt;/h2&gt;

&lt;p&gt;The build and release process is also documented.&lt;/p&gt;

&lt;p&gt;Each build includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;version
&lt;/li&gt;
&lt;li&gt;commit hash
&lt;/li&gt;
&lt;li&gt;tag
&lt;/li&gt;
&lt;li&gt;CI reference
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This allows anyone to trace how a distributed app was produced.&lt;/p&gt;




&lt;h2&gt;
  
  
  What this means
&lt;/h2&gt;

&lt;p&gt;You do not have to rely on claims.&lt;/p&gt;

&lt;p&gt;You can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;inspect the code
&lt;/li&gt;
&lt;li&gt;verify storage behavior
&lt;/li&gt;
&lt;li&gt;review cryptographic operations
&lt;/li&gt;
&lt;li&gt;confirm data handling
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The mobile app is fully transparent by design.&lt;/p&gt;




&lt;h2&gt;
  
  
  Repository
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://github.com/toqenapp/mobile-react-native" rel="noopener noreferrer"&gt;https://github.com/toqenapp/mobile-react-native&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Product access:
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS (App Store): search for “toqen.app”&lt;/li&gt;
&lt;li&gt;Android (closed testing): &lt;a href="https://forms.gle/f9FcbHyHJiajmFWV7" rel="noopener noreferrer"&gt;https://forms.gle/f9FcbHyHJiajmFWV7&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Typical use cases include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SaaS platforms&lt;/li&gt;
&lt;li&gt;gated digital content&lt;/li&gt;
&lt;li&gt;memberships&lt;/li&gt;
&lt;li&gt;online education environments&lt;/li&gt;
&lt;li&gt;event access systems&lt;/li&gt;
&lt;li&gt;other products requiring time-bound and policy-defined authorization&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;Building continues.&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>authentication</category>
      <category>infosec</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>The Paradox: The More Secure the Product, the Less People Trust It</title>
      <dc:creator>A</dc:creator>
      <pubDate>Tue, 14 Apr 2026 00:45:51 +0000</pubDate>
      <link>https://dev.to/antonmb/the-paradox-the-more-secure-the-product-the-less-people-trust-it-acb</link>
      <guid>https://dev.to/antonmb/the-paradox-the-more-secure-the-product-the-less-people-trust-it-acb</guid>
      <description>&lt;p&gt;Over the past few days, early feedback on the Toqen mobile app has been coming in.&lt;/p&gt;

&lt;p&gt;The reaction was not what you might expect.&lt;/p&gt;

&lt;p&gt;Not curiosity.&lt;br&gt;&lt;br&gt;
Not technical questions.&lt;br&gt;&lt;br&gt;
But hesitation.&lt;/p&gt;

&lt;p&gt;People are reluctant to install it.&lt;/p&gt;




&lt;h2&gt;
  
  
  First reaction defines everything
&lt;/h2&gt;

&lt;p&gt;The moment a product is perceived as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a password manager
&lt;/li&gt;
&lt;li&gt;a security tool
&lt;/li&gt;
&lt;li&gt;something that controls access
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;it is immediately placed into a high-risk mental category.&lt;/p&gt;

&lt;p&gt;From there, the default response is simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Better not touch it.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This happens before any technical understanding.&lt;/p&gt;




&lt;h2&gt;
  
  
  Architecture is invisible
&lt;/h2&gt;

&lt;p&gt;This is where things become interesting.&lt;/p&gt;

&lt;p&gt;Toqen is designed around a few strict principles:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;minimal data involvement
&lt;/li&gt;
&lt;li&gt;device-first trust model
&lt;/li&gt;
&lt;li&gt;no reliance on centralized sensitive storage
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;At a system level, this means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;cryptographic keys are generated on the device
&lt;/li&gt;
&lt;li&gt;secrets are not transmitted or stored centrally
&lt;/li&gt;
&lt;li&gt;access is verified through signed challenges
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But none of this is visible to the user.&lt;/p&gt;

&lt;p&gt;Architecture does not communicate itself.&lt;/p&gt;




&lt;h2&gt;
  
  
  Meanwhile, in other products
&lt;/h2&gt;

&lt;p&gt;Users regularly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;share personal data
&lt;/li&gt;
&lt;li&gt;allow tracking
&lt;/li&gt;
&lt;li&gt;grant broad permissions
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;in applications that are perceived as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;social
&lt;/li&gt;
&lt;li&gt;entertainment
&lt;/li&gt;
&lt;li&gt;“harmless”
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Even when those systems process significantly more data.&lt;/p&gt;




&lt;h2&gt;
  
  
  The asymmetry
&lt;/h2&gt;

&lt;p&gt;This leads to a consistent pattern:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;systems designed to &lt;strong&gt;protect&lt;/strong&gt; are treated with suspicion
&lt;/li&gt;
&lt;li&gt;systems that &lt;strong&gt;collect data&lt;/strong&gt; are treated with trust
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Not because of their architecture.&lt;/p&gt;

&lt;p&gt;But because of how they are perceived.&lt;/p&gt;




&lt;h2&gt;
  
  
  Trust is not a technical property
&lt;/h2&gt;

&lt;p&gt;Security does not automatically produce trust.&lt;/p&gt;

&lt;p&gt;Correct architecture does not automatically produce trust.&lt;/p&gt;

&lt;p&gt;Trust depends on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;perception
&lt;/li&gt;
&lt;li&gt;clarity
&lt;/li&gt;
&lt;li&gt;predictability
&lt;/li&gt;
&lt;li&gt;ability to verify
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Without these, even a strong system remains opaque.&lt;/p&gt;




&lt;h2&gt;
  
  
  What actually helps
&lt;/h2&gt;

&lt;p&gt;If trust cannot be assumed, it must be built differently.&lt;/p&gt;

&lt;p&gt;Not through statements.&lt;/p&gt;

&lt;p&gt;Through &lt;strong&gt;verifiability&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;One practical step is making the system inspectable.&lt;/p&gt;

&lt;p&gt;The Toqen mobile app is being prepared for open source release.&lt;/p&gt;

&lt;p&gt;This allows anyone to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;review how the system works
&lt;/li&gt;
&lt;li&gt;understand data flows
&lt;/li&gt;
&lt;li&gt;validate design decisions
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Simplified flow (high level)
&lt;/h2&gt;

&lt;p&gt;The authentication model is based on a challenge-response approach:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;A login request is created (QR contains a temporary challenge)
&lt;/li&gt;
&lt;li&gt;The device scans the QR
&lt;/li&gt;
&lt;li&gt;The challenge is signed using a device private key
&lt;/li&gt;
&lt;li&gt;The server verifies the signature using the stored public key
&lt;/li&gt;
&lt;li&gt;Access is granted
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Key properties:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;no reusable tokens
&lt;/li&gt;
&lt;li&gt;no shared secrets in transit
&lt;/li&gt;
&lt;li&gt;short-lived challenges
&lt;/li&gt;
&lt;li&gt;device-bound authorization
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Core principle
&lt;/h2&gt;

&lt;p&gt;Data is involved only within the scope required to complete an access operation.&lt;/p&gt;

&lt;p&gt;Critical elements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;are generated on the device
&lt;/li&gt;
&lt;li&gt;remain on the device
&lt;/li&gt;
&lt;li&gt;are never exposed in raw form
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The server operates only as a verifier.&lt;/p&gt;




&lt;h2&gt;
  
  
  Better to see than to hear
&lt;/h2&gt;

&lt;p&gt;There is a simple idea:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Better to see once than hear a hundred times.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Trust improves when systems can be explored directly.&lt;/p&gt;

&lt;p&gt;The app is currently:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;in testing on Google Play &lt;em&gt;(access available on request)&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;available in release form on the App Store
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Search: &lt;strong&gt;toqen.app&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Final thought
&lt;/h2&gt;

&lt;p&gt;Security alone is not enough.&lt;/p&gt;

&lt;p&gt;If a system is not understandable, it will not be trusted.&lt;/p&gt;

&lt;p&gt;The direction forward is clear:&lt;/p&gt;

&lt;p&gt;build systems that are not only secure,&lt;br&gt;&lt;br&gt;
but also &lt;strong&gt;transparent, inspectable, and predictable&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>authentication</category>
      <category>cryptography</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Access-First Authentication with QR + Device Signatures</title>
      <dc:creator>A</dc:creator>
      <pubDate>Mon, 13 Apr 2026 10:36:29 +0000</pubDate>
      <link>https://dev.to/antonmb/access-first-authentication-with-qr-device-signatures-20f0</link>
      <guid>https://dev.to/antonmb/access-first-authentication-with-qr-device-signatures-20f0</guid>
      <description>&lt;p&gt;Toqen.app is now live on the App Store.&lt;/p&gt;

&lt;p&gt;This is an attempt to rethink authentication from an access-first perspective: instead of managing identities and credentials, focus on granting access in real time, per request.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why rethink authentication
&lt;/h2&gt;

&lt;p&gt;Most systems still rely on reusable credentials:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;passwords&lt;/li&gt;
&lt;li&gt;session tokens&lt;/li&gt;
&lt;li&gt;API keys&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These introduce predictable problems:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;credential leaks&lt;/li&gt;
&lt;li&gt;replay attacks&lt;/li&gt;
&lt;li&gt;uncontrolled sharing&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Even with MFA, the core model remains static.&lt;/p&gt;




&lt;h2&gt;
  
  
  Core idea
&lt;/h2&gt;

&lt;p&gt;Each access request should be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;short-lived&lt;/li&gt;
&lt;li&gt;single-use&lt;/li&gt;
&lt;li&gt;bound to a device&lt;/li&gt;
&lt;li&gt;cryptographically verifiable&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Instead of storing secrets, the system verifies a signed challenge.&lt;/p&gt;




&lt;h2&gt;
  
  
  Flow
&lt;/h2&gt;

&lt;p&gt;User opens login page&lt;br&gt;
↓&lt;br&gt;
Server generates request&lt;br&gt;
↓&lt;br&gt;
QR code is displayed&lt;br&gt;
↓&lt;br&gt;
Mobile app scans QR&lt;br&gt;
↓&lt;br&gt;
User confirms access&lt;br&gt;
↓&lt;br&gt;
Device signs challenge&lt;br&gt;
↓&lt;br&gt;
Server verifies signature&lt;br&gt;
↓&lt;br&gt;
Access granted&lt;/p&gt;




&lt;h2&gt;
  
  
  QR format
&lt;/h2&gt;

&lt;p&gt;QR does not contain secrets.&lt;/p&gt;

&lt;p&gt;Example:&lt;/p&gt;

&lt;p&gt;toqen://auth?request_id=91f2d&amp;amp;challenge=8fa92c1a&amp;amp;expires=1710000000&lt;/p&gt;

&lt;p&gt;Properties:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;expires in 30–60 seconds&lt;/li&gt;
&lt;li&gt;single-use&lt;/li&gt;
&lt;li&gt;cannot be replayed&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Device model
&lt;/h2&gt;

&lt;p&gt;On first launch:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;device generates key pair&lt;/li&gt;
&lt;li&gt;private key → stored in secure storage&lt;/li&gt;
&lt;li&gt;public key → registered on server&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Signing:&lt;/p&gt;

&lt;p&gt;signature = sign(challenge, device_private_key)&lt;/p&gt;

&lt;p&gt;Verification:&lt;/p&gt;

&lt;p&gt;verify(signature, device_public_key)&lt;/p&gt;




&lt;h2&gt;
  
  
  Security properties
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;no reusable credentials&lt;/li&gt;
&lt;li&gt;no secrets in QR&lt;/li&gt;
&lt;li&gt;replay protection via TTL + single-use&lt;/li&gt;
&lt;li&gt;device-bound authorization&lt;/li&gt;
&lt;li&gt;server stores only public keys&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Vault model
&lt;/h2&gt;

&lt;p&gt;Sensitive data is encrypted client-side:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;encrypted_vault&lt;/li&gt;
&lt;li&gt;AES-256-GCM&lt;/li&gt;
&lt;li&gt;vault_key stored in secure storage&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Server never has decryption capability.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where this fits
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;admin access&lt;/li&gt;
&lt;li&gt;internal tools&lt;/li&gt;
&lt;li&gt;high-risk operations&lt;/li&gt;
&lt;li&gt;temporary access flows&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Current status
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;iOS app is live on the App Store&lt;/li&gt;
&lt;li&gt;Android version is in testing&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Open for feedback
&lt;/h2&gt;

&lt;p&gt;If you are working on authentication, security, or access control systems — feedback is welcome.&lt;/p&gt;

&lt;p&gt;Contact: &lt;a href="https://www.toqen.app/about#contacts" rel="noopener noreferrer"&gt;https://www.toqen.app/about#contacts&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Android early access: &lt;a href="https://forms.gle/f9FcbHyHJiajmFWV7" rel="noopener noreferrer"&gt;https://forms.gle/f9FcbHyHJiajmFWV7&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;Building continues.&lt;/p&gt;

</description>
      <category>ux</category>
      <category>mobile</category>
      <category>authentication</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Access without passwords — short demo</title>
      <dc:creator>A</dc:creator>
      <pubDate>Wed, 08 Apr 2026 06:15:55 +0000</pubDate>
      <link>https://dev.to/antonmb/access-without-passwords-short-demo-19i5</link>
      <guid>https://dev.to/antonmb/access-without-passwords-short-demo-19i5</guid>
      <description></description>
      <category>authentication</category>
      <category>innovation</category>
      <category>access</category>
      <category>ux</category>
    </item>
    <item>
      <title>Toqen.app mobile testing is now live on iOS</title>
      <dc:creator>A</dc:creator>
      <pubDate>Tue, 07 Apr 2026 17:18:34 +0000</pubDate>
      <link>https://dev.to/antonmb/toqenapp-mobile-testing-is-now-live-on-ios-5h05</link>
      <guid>https://dev.to/antonmb/toqenapp-mobile-testing-is-now-live-on-ios-5h05</guid>
      <description>&lt;p&gt;I am glad to share that Toqen.app mobile testing is now live on iOS.&lt;/p&gt;

&lt;p&gt;If you would like to try how access-first authentication works in real usage before the official release, please fill out a short form and we will open access (link below).&lt;/p&gt;

&lt;p&gt;For Android users, testing is already ongoing on Google Play.&lt;/p&gt;

&lt;p&gt;Two scenarios are currently available:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Sign in via the mobile app — open the “Services” tab, tap “Sign in”, and you are you are instantly signed in in the browser &lt;/li&gt;
&lt;li&gt;Sign in via QR — open Toqen.app or Litseller.com on your desktop, scan the QR code or enter the OTP in the app, and confirm access&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The idea is simple: access is confirmed at the moment of login. No separation between sign up and login. The session is created securely and has a limited lifetime.&lt;/p&gt;

&lt;p&gt;👉Join: &lt;a href="https://forms.gle/5LhYEyj87aNLuKpN9" rel="noopener noreferrer"&gt;https://forms.gle/5LhYEyj87aNLuKpN9&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;👉Honest feedback is highly appreciated: &lt;a href="https://forms.gle/S7mmzji5ftGKZZys9" rel="noopener noreferrer"&gt;https://forms.gle/S7mmzji5ftGKZZys9&lt;/a&gt;&lt;/p&gt;

</description>
      <category>authentication</category>
      <category>ios</category>
      <category>android</category>
      <category>security</category>
    </item>
    <item>
      <title>Hi everyone :wave: Have a great Friday!
I have just released a mobile app - Toqen - now available in closed testing.
The idea is simple: Scan Confirm Access.</title>
      <dc:creator>A</dc:creator>
      <pubDate>Fri, 03 Apr 2026 14:08:42 +0000</pubDate>
      <link>https://dev.to/antonmb/hi-everyone-wave-have-a-great-friday-i-have-just-released-a-mobile-app-toqen-now-available-3dbh</link>
      <guid>https://dev.to/antonmb/hi-everyone-wave-have-a-great-friday-i-have-just-released-a-mobile-app-toqen-now-available-3dbh</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/toqenapp/toqen-mobile-access-in-2-steps-1295" class="crayons-story__hidden-navigation-link"&gt;🚀 Toqen Mobile: access in 2 steps&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;
          &lt;a class="crayons-logo crayons-logo--l" href="/toqenapp"&gt;
            &lt;img alt="Toqen.app logo" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F12579%2Fc1a9ea36-d31e-4203-b400-2bd54ddbad90.png" class="crayons-logo__image" width="800" height="800"&gt;
          &lt;/a&gt;

          &lt;a href="/antonmb" class="crayons-avatar  crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3667847%2F5517e5b7-498d-45aa-995d-6628e9d67176.jpeg" alt="antonmb profile" class="crayons-avatar__image" width="225" height="225"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/antonmb" class="crayons-story__secondary fw-medium m:hidden"&gt;
              A
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                A
                
              
              &lt;div id="story-author-preview-content-3449856" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/antonmb" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3667847%2F5517e5b7-498d-45aa-995d-6628e9d67176.jpeg" class="crayons-avatar__image" alt="" width="225" height="225"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;A&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

            &lt;span&gt;
              &lt;span class="crayons-story__tertiary fw-normal"&gt; for &lt;/span&gt;&lt;a href="/toqenapp" class="crayons-story__secondary fw-medium"&gt;Toqen.app&lt;/a&gt;
            &lt;/span&gt;
          &lt;/div&gt;
          &lt;a href="https://dev.to/toqenapp/toqen-mobile-access-in-2-steps-1295" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Apr 3&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/toqenapp/toqen-mobile-access-in-2-steps-1295" id="article-link-3449856"&gt;
          🚀 Toqen Mobile: access in 2 steps
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/authentication"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;authentication&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/security"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;security&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/mobile"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;mobile&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cryptography"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cryptography&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/toqenapp/toqen-mobile-access-in-2-steps-1295" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/raised-hands-74b2099fd66a39f2d7eed9305ee0f4553df0eb7b4f11b01b6b1b499973048fe5.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;4&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/toqenapp/toqen-mobile-access-in-2-steps-1295#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
            
              &lt;span class="bm-initial crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
              &lt;span class="bm-success crayons-icon c-btn__icon"&gt;
                

              &lt;/span&gt;
            
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Instant Access for Users, Fast Integration for Developers</title>
      <dc:creator>A</dc:creator>
      <pubDate>Sat, 07 Mar 2026 03:49:17 +0000</pubDate>
      <link>https://dev.to/antonmb/instant-access-for-users-fast-integration-for-developers-38jo</link>
      <guid>https://dev.to/antonmb/instant-access-for-users-fast-integration-for-developers-38jo</guid>
      <description>&lt;p&gt;Access infrastructure often becomes one of the most complex parts of a product.&lt;/p&gt;

&lt;p&gt;Login flows evolve.&lt;br&gt;&lt;br&gt;
Security checks appear.&lt;br&gt;&lt;br&gt;
Recovery scenarios multiply.&lt;br&gt;&lt;br&gt;
Protection against abuse becomes necessary.&lt;/p&gt;

&lt;p&gt;Over time this layer grows into a large subsystem that becomes increasingly difficult to modify safely.&lt;/p&gt;

&lt;p&gt;At the same time every new product still needs a reliable way to provide access.&lt;/p&gt;

&lt;p&gt;This leads to a practical engineering question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How can access be implemented without building a large authentication system inside the product?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Toqen.app was designed with a simple goal:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Instant access for users
&lt;/li&gt;
&lt;li&gt;Fast integration for developers&lt;/li&gt;
&lt;/ul&gt;



&lt;p&gt;Instead of implementing authentication infrastructure inside the product, the product connects to an access layer through a lightweight SDK.&lt;/p&gt;

&lt;p&gt;From the product’s perspective the integration is intentionally minimal.&lt;/p&gt;

&lt;p&gt;In most cases it requires only two things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Install and connect the SDK
&lt;/li&gt;
&lt;li&gt;Store the minimal user record required by the product&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Everything related to access infrastructure is handled by the access layer.&lt;/p&gt;

&lt;p&gt;This means the product team does &lt;strong&gt;not&lt;/strong&gt; need to implement:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;login flows
&lt;/li&gt;
&lt;li&gt;session infrastructure
&lt;/li&gt;
&lt;li&gt;cryptographic verification
&lt;/li&gt;
&lt;li&gt;abuse-prevention mechanisms
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In practice the basic integration typically takes &lt;strong&gt;around 10 minutes&lt;/strong&gt;.&lt;/p&gt;


&lt;h2&gt;
  
  
  Development Mode
&lt;/h2&gt;

&lt;p&gt;The SDK includes a development mode designed for extremely fast local setup.&lt;/p&gt;

&lt;p&gt;In development environments the SDK runs with a built-in &lt;strong&gt;in-memory store&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;This allows the access flow to work immediately without configuring any database.&lt;/p&gt;

&lt;p&gt;Developers can start building product features right away while the access layer is already functioning.&lt;/p&gt;


&lt;h2&gt;
  
  
  Moving to Production
&lt;/h2&gt;

&lt;p&gt;When the product is ready for production, the product stores its user data in its own database.&lt;/p&gt;

&lt;p&gt;At this stage the product typically keeps a minimal user record such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;an internal user identifier
&lt;/li&gt;
&lt;li&gt;product-specific data
&lt;/li&gt;
&lt;li&gt;optional profile information
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The SDK documentation provides clear step-by-step guides for connecting existing databases without redesigning the product architecture.&lt;/p&gt;


&lt;h2&gt;
  
  
  What the Integration Looks Like
&lt;/h2&gt;

&lt;p&gt;A simplified example might look like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="nx"&gt;npm&lt;/span&gt; &lt;span class="nx"&gt;install&lt;/span&gt; &lt;span class="p"&gt;@&lt;/span&gt;&lt;span class="nd"&gt;toqenapp&lt;/span&gt;&lt;span class="sr"&gt;/sd&lt;/span&gt;&lt;span class="err"&gt;k
&lt;/span&gt;
&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;createToqen&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;@toqenapp/sdk&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;toqen&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createToqen&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;siteKey&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;SITE_KEY&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;mode&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;development&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;callbacks&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;onLogin&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nx"&gt;onLogout&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;})&lt;/span&gt;

&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;use&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;toqen&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;middleware&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;

&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;/dashboard&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nx"&gt;toqen&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;authorize&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
  &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;Protected content&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="nx"&gt;app&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;/profile&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="nx"&gt;toqen&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;authorize&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;
  &lt;span class="k"&gt;async &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;

    &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;user&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;db&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;users&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;findById&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;req&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;toqen&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;userId&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

    &lt;span class="nx"&gt;res&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;user&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;

  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  What the SDK Does
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;toqen.middleware()&lt;/code&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;checks the access cookie&lt;/li&gt;
&lt;li&gt;validates the signature&lt;/li&gt;
&lt;li&gt;decodes claims&lt;/li&gt;
&lt;li&gt;adds the access context to req.toqen&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code&gt;toqen.authorize()&lt;/code&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;checks for valid access&lt;/li&gt;
&lt;li&gt;returns 401 if access is not present&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Reliability and Responsibility
&lt;/h2&gt;

&lt;p&gt;The architecture separates responsibilities clearly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Toqen.app handles&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;access infrastructure&lt;/li&gt;
&lt;li&gt;access sessions&lt;/li&gt;
&lt;li&gt;security mechanisms around access&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;The product handles&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;its own database&lt;/li&gt;
&lt;li&gt;business logic&lt;/li&gt;
&lt;li&gt;product functionality&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Security updates and improvements to the access infrastructure are maintained by the Toqen.app platform.&lt;/p&gt;

&lt;p&gt;This allows product teams to avoid maintaining complex authentication systems inside their own codebase.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why This Matters
&lt;/h2&gt;

&lt;p&gt;For engineering teams this means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;extremely fast initial integration&lt;/li&gt;
&lt;li&gt;predictable architecture&lt;/li&gt;
&lt;li&gt;less security-sensitive code inside the product&lt;/li&gt;
&lt;li&gt;fewer infrastructure components to maintain&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Teams can focus on building product functionality instead of maintaining authentication infrastructure.&lt;/p&gt;




&lt;h2&gt;
  
  
  Pilot Integrations
&lt;/h2&gt;

&lt;p&gt;We are currently opening pilot integrations for Toqen.app.&lt;/p&gt;

&lt;p&gt;The goal is simple:&lt;/p&gt;

&lt;p&gt;demonstrate how access infrastructure can remain lightweight while still providing secure and reliable access.&lt;/p&gt;

&lt;p&gt;If you are interested in exploring the approach or testing the integration in your environment, feel free to reach out.&lt;/p&gt;

</description>
      <category>authentication</category>
      <category>security</category>
      <category>backend</category>
      <category>architecture</category>
    </item>
    <item>
      <title>Architectural Asymmetry in Authentication: Part 3 — Behavioral Automation and Phishing Efficiency</title>
      <dc:creator>A</dc:creator>
      <pubDate>Fri, 06 Mar 2026 18:06:32 +0000</pubDate>
      <link>https://dev.to/antonmb/architectural-asymmetry-in-authentication-part-3-behavioral-automation-and-phishing-efficiency-2gg2</link>
      <guid>https://dev.to/antonmb/architectural-asymmetry-in-authentication-part-3-behavioral-automation-and-phishing-efficiency-2gg2</guid>
      <description>&lt;p&gt;In &lt;strong&gt;Part 1&lt;/strong&gt; we introduced the concept of &lt;strong&gt;architectural asymmetry in authentication&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;In &lt;strong&gt;Part 2&lt;/strong&gt; we examined how &lt;strong&gt;disclosure before context&lt;/strong&gt; creates structural exposure inside authentication flows.&lt;/p&gt;

&lt;p&gt;This article explores another important effect of authentication architecture:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;behavioral automation.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When authentication patterns repeat across services and over time, user behavior becomes automatic. That automation directly influences the effectiveness of phishing attacks.&lt;/p&gt;

&lt;p&gt;The issue is not user awareness.&lt;/p&gt;

&lt;p&gt;The issue is &lt;strong&gt;pattern conditioning created by system design.&lt;/strong&gt;&lt;/p&gt;




&lt;h1&gt;
  
  
  How Authentication Patterns Become Automatic
&lt;/h1&gt;

&lt;p&gt;Most authentication systems follow a familiar structure:&lt;br&gt;
Page loads&lt;br&gt;
→ User enters identifier&lt;br&gt;
→ User enters secret&lt;br&gt;
→ Access granted&lt;/p&gt;

&lt;p&gt;This sequence appears across thousands of services.&lt;/p&gt;

&lt;p&gt;Because the pattern repeats constantly, users begin executing it &lt;strong&gt;without conscious verification&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Login becomes less of a decision and more of a reflex.&lt;/p&gt;

&lt;p&gt;As this automation forms, several types of verification weaken:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;domain verification&lt;/li&gt;
&lt;li&gt;redirect origin awareness&lt;/li&gt;
&lt;li&gt;interface inconsistency detection&lt;/li&gt;
&lt;li&gt;unexpected authentication step recognition&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The human brain optimizes repeated actions for speed.&lt;/p&gt;

&lt;p&gt;Authentication becomes &lt;strong&gt;habitual interaction&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Cognitive Load and Time Pressure
&lt;/h1&gt;

&lt;p&gt;Authentication often happens under time pressure.&lt;/p&gt;

&lt;p&gt;Typical situations include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;internal systems accessed many times per day&lt;/li&gt;
&lt;li&gt;consumer services opened quickly on mobile&lt;/li&gt;
&lt;li&gt;short session lifetimes&lt;/li&gt;
&lt;li&gt;frequent reauthentication policies&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Under these conditions the mental model becomes simple:&lt;br&gt;
Open page&lt;br&gt;
→ complete expected steps&lt;br&gt;
→ continue work&lt;/p&gt;

&lt;p&gt;When a phishing page reproduces the expected pattern, the user’s cognitive system interprets the interaction as familiar.&lt;/p&gt;

&lt;p&gt;The attack succeeds not because the user is careless.&lt;/p&gt;

&lt;p&gt;It succeeds because &lt;strong&gt;the pattern matches expectation&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Why Phishing Pages Are So Effective
&lt;/h1&gt;

&lt;p&gt;Phishing attacks rarely introduce new interaction models.&lt;/p&gt;

&lt;p&gt;Instead attackers reproduce &lt;strong&gt;the exact interaction pattern users already know&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Typical phishing pages mimic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;login page layout&lt;/li&gt;
&lt;li&gt;identifier input field&lt;/li&gt;
&lt;li&gt;secret entry step&lt;/li&gt;
&lt;li&gt;redirect flow&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Because the interaction structure matches expectation, users often complete the process &lt;strong&gt;before deeper verification occurs&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The attack relies on &lt;strong&gt;behavioral predictability&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Transferable Secrets Amplify the Risk
&lt;/h1&gt;

&lt;p&gt;Behavioral automation becomes far more dangerous when authentication relies on &lt;strong&gt;transferable secrets&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;passwords&lt;/li&gt;
&lt;li&gt;manually entered OTP codes&lt;/li&gt;
&lt;li&gt;recovery codes&lt;/li&gt;
&lt;li&gt;shared authentication factors&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a user enters such a secret into a phishing interface, the attacker can reuse it.&lt;/p&gt;

&lt;p&gt;A behavioral mistake becomes &lt;strong&gt;persistent compromise&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Even short-lived secrets can be exploited if interception occurs within the valid window.&lt;/p&gt;

&lt;p&gt;The combination of behavioral automation transferable secrets creates a highly efficient attack path.&lt;/p&gt;




&lt;h1&gt;
  
  
  Why Security Training Has Limited Effect
&lt;/h1&gt;

&lt;p&gt;Security awareness training encourages users to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;verify domains&lt;/li&gt;
&lt;li&gt;avoid suspicious links&lt;/li&gt;
&lt;li&gt;check login pages carefully&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This helps.&lt;/p&gt;

&lt;p&gt;But training competes with a powerful opposing force:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;habit formation.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When users repeat the same authentication pattern dozens of times per day, automatic behavior dominates.&lt;/p&gt;

&lt;p&gt;Even well-trained users may act automatically when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;they are under time pressure&lt;/li&gt;
&lt;li&gt;the interface looks familiar&lt;/li&gt;
&lt;li&gt;the expected login pattern appears&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Education improves resilience.&lt;/p&gt;

&lt;p&gt;It does not eliminate &lt;strong&gt;behavioral conditioning created by authentication architecture&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Breaking the Behavioral Pattern
&lt;/h1&gt;

&lt;p&gt;Reducing phishing efficiency requires weakening predictable authentication patterns.&lt;/p&gt;

&lt;p&gt;Several architectural approaches help achieve this.&lt;/p&gt;

&lt;h3&gt;
  
  
  Device-Bound Confirmation
&lt;/h3&gt;

&lt;p&gt;Authentication tied to a device rather than manual secret entry.&lt;/p&gt;

&lt;h3&gt;
  
  
  Challenge-Response Authentication
&lt;/h3&gt;

&lt;p&gt;User confirmation occurs in a trusted environment rather than inside the requesting page.&lt;/p&gt;

&lt;h3&gt;
  
  
  Out-of-Band Verification
&lt;/h3&gt;

&lt;p&gt;Confirmation happens through a separate trusted channel.&lt;/p&gt;

&lt;h3&gt;
  
  
  Cryptographic Authenticators
&lt;/h3&gt;

&lt;p&gt;Hardware-backed keys and passkeys replace typed secrets.&lt;/p&gt;

&lt;p&gt;The key principle remains the same:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;confirmation happens in a trusted context, not inside the requesting interface&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This significantly reduces the impact of page imitation.&lt;/p&gt;




&lt;h1&gt;
  
  
  Context Changes the Pattern
&lt;/h1&gt;

&lt;p&gt;When authentication begins with &lt;strong&gt;context validation&lt;/strong&gt; rather than identifier disclosure, the interaction model changes.&lt;/p&gt;

&lt;p&gt;Instead of repeated manual steps, confirmation becomes tied to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;device possession&lt;/li&gt;
&lt;li&gt;session continuity&lt;/li&gt;
&lt;li&gt;cryptographic challenge&lt;/li&gt;
&lt;li&gt;trusted environment signals&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users perform &lt;strong&gt;less repetitive secret entry&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Behavioral automation weakens.&lt;/p&gt;

&lt;p&gt;Attackers can no longer rely on a universal login pattern being executed automatically.&lt;/p&gt;




&lt;h1&gt;
  
  
  Architectural Implication
&lt;/h1&gt;

&lt;p&gt;Authentication security depends not only on cryptography and protocols, but also on &lt;strong&gt;behavioral patterns created by system design&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Identity-first systems encourage repeated disclosure of identifiers and secrets.&lt;/p&gt;

&lt;p&gt;Over time this produces a stable loop:&lt;br&gt;
open page&lt;br&gt;
→ disclose&lt;br&gt;
→ proceed&lt;/p&gt;

&lt;p&gt;Attackers exploit the predictability of this loop.&lt;/p&gt;

&lt;p&gt;Architectural changes that reduce repeated secret entry and bind confirmation to trusted contexts weaken this predictability.&lt;/p&gt;

&lt;p&gt;This does not eliminate phishing entirely.&lt;/p&gt;

&lt;p&gt;But it changes &lt;strong&gt;the economics of the attack&lt;/strong&gt;.&lt;/p&gt;




&lt;h1&gt;
  
  
  Looking Ahead
&lt;/h1&gt;

&lt;p&gt;Authentication systems are gradually moving toward models where:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;manual secret entry becomes rare&lt;/li&gt;
&lt;li&gt;confirmation is device-bound&lt;/li&gt;
&lt;li&gt;session context influences authentication decisions&lt;/li&gt;
&lt;li&gt;disclosure happens only when strictly necessary&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These changes reduce both compromise scale and behavioral exploitation.&lt;/p&gt;

&lt;p&gt;The shift is gradual, but the architectural direction is becoming clearer.&lt;/p&gt;




&lt;p&gt;In &lt;strong&gt;Part 4&lt;/strong&gt;, we will examine how &lt;strong&gt;transferable secrets amplify compromise scale&lt;/strong&gt; and why reducing their role fundamentally changes the attack surface of authentication systems.&lt;/p&gt;

</description>
      <category>security</category>
      <category>authentication</category>
      <category>cybersecurity</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Where AI Will Not Replace Humans Anytime Soon</title>
      <dc:creator>A</dc:creator>
      <pubDate>Fri, 06 Mar 2026 07:47:53 +0000</pubDate>
      <link>https://dev.to/antonmb/where-ai-will-not-replace-humans-anytime-soon-4f6k</link>
      <guid>https://dev.to/antonmb/where-ai-will-not-replace-humans-anytime-soon-4f6k</guid>
      <description>&lt;p&gt;If AI ever “takes over the world”, it probably will not happen with weapons.&lt;/p&gt;

&lt;p&gt;It will happen much more quietly — by gradually taking over human work.&lt;/p&gt;

&lt;p&gt;We are already seeing this shift.&lt;/p&gt;

&lt;p&gt;AI tools are replacing many routine tasks across industries. But the impact is not uniform. Some professions are changing rapidly, while others remain far more resistant to automation.&lt;/p&gt;

&lt;p&gt;Here are a few areas where humans are likely to remain essential for a long time.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. Physical Repair and Service
&lt;/h2&gt;

&lt;p&gt;The real world is messy.&lt;/p&gt;

&lt;p&gt;Unlike software systems, physical environments are rarely predictable or standardized.&lt;/p&gt;

&lt;p&gt;Every repair job can involve:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;different equipment
&lt;/li&gt;
&lt;li&gt;unexpected failures
&lt;/li&gt;
&lt;li&gt;incomplete documentation
&lt;/li&gt;
&lt;li&gt;unique environmental conditions
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A mechanic repairing an engine or an electrician troubleshooting wiring constantly deals with situations that cannot easily be reduced to structured data.&lt;/p&gt;

&lt;p&gt;Robotics will eventually improve, but deploying adaptable machines capable of handling this complexity at scale is still far away.&lt;/p&gt;

&lt;p&gt;For now, humans remain far better at solving problems in unpredictable environments.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. B2B Sales
&lt;/h2&gt;

&lt;p&gt;Enterprise sales are not just about presenting information.&lt;/p&gt;

&lt;p&gt;They are about:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;trust
&lt;/li&gt;
&lt;li&gt;negotiation
&lt;/li&gt;
&lt;li&gt;relationships
&lt;/li&gt;
&lt;li&gt;timing
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;AI can already help generate emails, proposals, and reports.&lt;/p&gt;

&lt;p&gt;But closing a complex deal still depends heavily on human interaction and trust.&lt;/p&gt;

&lt;p&gt;Large contracts often involve informal communication, subtle signals during negotiations, and long-term relationship building.&lt;/p&gt;

&lt;p&gt;AI will become a powerful assistant in sales workflows, but replacing human sales professionals entirely is unlikely anytime soon.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Software Engineering
&lt;/h2&gt;

&lt;p&gt;AI is already transforming how code is written.&lt;/p&gt;

&lt;p&gt;Tools like AI coding assistants can generate code, suggest fixes, write tests, and even scaffold entire services.&lt;/p&gt;

&lt;p&gt;This significantly impacts routine development tasks.&lt;/p&gt;

&lt;p&gt;In particular:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;junior-level tasks are increasingly automated&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;many middle-level tasks are becoming easier with AI&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;However, higher-level engineering work remains difficult to automate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;system architecture
&lt;/li&gt;
&lt;li&gt;large-scale system design
&lt;/li&gt;
&lt;li&gt;complex integrations
&lt;/li&gt;
&lt;li&gt;engineering trade-offs
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The role of developers is shifting.&lt;/p&gt;

&lt;p&gt;Less time writing boilerplate code.&lt;br&gt;&lt;br&gt;
More time designing systems and making architectural decisions.&lt;/p&gt;

&lt;p&gt;The real value of developers increasingly comes from &lt;strong&gt;system thinking rather than typing code&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. DevOps and Infrastructure
&lt;/h2&gt;

&lt;p&gt;Production systems rarely behave like clean diagrams in documentation.&lt;/p&gt;

&lt;p&gt;Real infrastructure often includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;legacy systems
&lt;/li&gt;
&lt;li&gt;unusual configurations
&lt;/li&gt;
&lt;li&gt;partial documentation
&lt;/li&gt;
&lt;li&gt;unexpected operational failures
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;When a system goes down at 3 AM, solving the problem usually requires experience, judgment, and the ability to understand complex system behavior quickly.&lt;/p&gt;

&lt;p&gt;AI tools can help analyze logs and suggest solutions.&lt;/p&gt;

&lt;p&gt;But responsibility for diagnosing and fixing incidents still falls on experienced engineers.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. Cybersecurity
&lt;/h2&gt;

&lt;p&gt;Cybersecurity is fundamentally different from many other technical fields.&lt;/p&gt;

&lt;p&gt;It is not just about solving technical problems.&lt;/p&gt;

&lt;p&gt;It is about defending systems against &lt;strong&gt;intelligent adversaries&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Attackers constantly change tactics, adapt tools, and search for new weaknesses.&lt;/p&gt;

&lt;p&gt;AI will certainly help automate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;threat detection
&lt;/li&gt;
&lt;li&gt;log analysis
&lt;/li&gt;
&lt;li&gt;vulnerability discovery
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But security ultimately remains a strategic battle between humans.&lt;/p&gt;

&lt;p&gt;As long as attackers continue to innovate, human expertise will remain essential.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Bigger Shift
&lt;/h2&gt;

&lt;p&gt;AI is not simply replacing professions.&lt;/p&gt;

&lt;p&gt;It is reshaping them.&lt;/p&gt;

&lt;p&gt;Routine and predictable tasks are increasingly automated, while the remaining work shifts toward:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;system thinking
&lt;/li&gt;
&lt;li&gt;responsibility and decision-making
&lt;/li&gt;
&lt;li&gt;working with uncertainty
&lt;/li&gt;
&lt;li&gt;operating in complex real-world environments
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In many fields, the future will not be &lt;strong&gt;humans vs AI&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It will be &lt;strong&gt;humans working with increasingly powerful tools&lt;/strong&gt; — focusing on the parts of the problem that machines still struggle to solve.&lt;/p&gt;




&lt;p&gt;If you want to explore these ideas further — especially system thinking, decision-making under uncertainty, and working in complex environments — these books are worth reading.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;a href="https://litseller.com/meadows-donella/thinking-in-systems-a-primer" rel="noopener noreferrer"&gt;Thinking in Systems — Donella Meadows&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;A foundational book about how complex systems behave and how feedback loops shape real-world outcomes.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;a href="https://litseller.com/tetlock-philip/superforecasting-the-art-and-science-of-prediction" rel="noopener noreferrer"&gt;Superforecasting — Philip Tetlock&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;A deep dive into how people can make better predictions and decisions in uncertain environments.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;a href="https://litseller.com/taleb-nassim-nicholas/skin-in-the-game-hidden-asymmetries-in-daily-life" rel="noopener noreferrer"&gt;Skin in the Game — Nassim Nicholas Taleb&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;A powerful perspective on responsibility, risk, and why decision-makers must face the consequences of their choices.&lt;/p&gt;

&lt;h3&gt;
  
  
  &lt;a href="https://litseller.com/epstein-david/range-why-generalists-triumph-in-a-specialized-world" rel="noopener noreferrer"&gt;Range — David Epstein&lt;/a&gt;
&lt;/h3&gt;

&lt;p&gt;An argument for broad thinking and interdisciplinary knowledge in a world that increasingly rewards adaptability.&lt;/p&gt;

&lt;p&gt;Short summaries of these books are available on &lt;strong&gt;&lt;a href="https://litseller.com" rel="noopener noreferrer"&gt;https://litseller.com&lt;/a&gt;&lt;/strong&gt; if you want to quickly understand their core ideas before deciding whether to read the full book.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>softwareengineering</category>
      <category>cybersecurity</category>
      <category>futureofwork</category>
    </item>
  </channel>
</rss>
