#identity
Wiki 6
- Agents as first-class identities Giving agents their own key pairs and signed event trails instead of running them through a shared bot account β attribution survives, but effort still doesn't
- don't sign in with google (the smart ape, 2026) A friend's three-year SaaS dies overnight when Google suspends his account β the thread walks through cascading SaaS lockout, four post-password-reset attack vectors, and a triage rule for when SSO is actually fine
- Ephemeral Credentials Short-lived credentials (β€1 day) where rotation is structural rather than scheduled β minted per session, expire on their own
- Google OAuth domain-takeover flaw (Truffle Security, Jan 2025) Buying a dead startup's domain for $12 lets you re-create old employee emails on Workspace and log into the dead company's Slack/Notion/Zoom via "Sign in with Google" β initially marked won't-fix, $1,337 bounty after public pressure
- Inverted claim onboarding Onboarding pattern where the AI agent registers first and a human "claims" it via OTP; until then, the agent has a one-recipient cap
- SSO concentration risk SSO trades distributed risk for concentrated risk β same expected loss in theory, dramatically worse failure mode in practice when the IdP terminates the relationship