RIP passwords
Raise your hand if you're terrible at remembering passwords. β
Good news. Last week, the World Wide Web Consortium approved WebAuthn, a new authentication standard for password-free logins.
How it works: WebAuthn is an API that lets websites communicate with security devices, and allows users to log into their online accounts using biometrics and authentication hardware like FIDO security keys.
WebAuthn is already supported by browsers like Chrome, Firefox, Edge and Safari. Android and Windows 10 also support the new standard.
The next step for WebAuthn? Websites need to integrate the standard. Dropbox, Facebook, GitHub, Salesforce, Stripe and Twitter are already on board.
Why this is important: WebAuthn is more secure than the weak passwords that a lot of people use to safeguard their online accounts. Three out of four people use duplicate passwords online, and 21 percent of people use passwords that are over 10 years old. π³
What does this mean for password managers like 1Password, PadLock, Dashlane, Google Titan and Blockvault? Time will tell. But not having a password at all is simpler than having to remember any password in the first place. π
Your agents stopped answering and started doing
Your agents call tools, write to databases and move money, so a wrong answer is now a wrong action, which is a considerably worse meeting. Arcjet runs policy before every LLM call, tool call, query and API request: prompt injection, sensitive data, bots, rate limits, spend quotas, and your own rules in Rego on top. It reads the OpenTelemetry you already emit, so switching it on is one environment variable, no code changes and nothing to deploy. Each check also reads the earlier steps in the same workflow, so an agent's tenth action gets judged against the first nine and not on its own. JavaScript, Python and Go SDKs all at 1.0, agent framework guards included, free tier to start on.


