Identity Is What Survives the Key
KeyFlux takes its name from an experiment in rapid key rotation. I explain what failed, what a telco QKD trial taught me, and why identity needs to survive changes to the cryptography beneath it.
KRNALI LABS / THINKING
Writing by Josh Bahlman on digital identity, security and AI.
KeyFlux takes its name from an experiment in rapid key rotation. I explain what failed, what a telco QKD trial taught me, and why identity needs to survive changes to the cryptography beneath it.
An AI agent deleted a production database during a code freeze. The incident shows why permissions need to be checked when an agent acts, even when its instructions are clear.
A standards update can leave an implementation out of date between audits. This article looks at tracking specification changes and checking their impact as part of the build process.
A valid credential is one input to a decision. A service still needs to check whether the holder meets its requirements, using current information and rules it can explain later.
How scoped, short-lived permissions keep AI agents accountable: who can delegate access, what an agent can do, and when that access ends.
When an agent calls a payment API, the service needs to know whose authority it carries and what that authority permits. I look at the limits of API keys and shared credentials in these exchanges.
Living in Denmark has made digital identity an ordinary part of my day. Getting the same convenience across borders means giving people more places to use the credentials they already hold.
These articles were originally published on KeyFlux. Their original dates and text are retained.