Home / Companies / Ory / Blog / March 2025

March 2025 Summaries

4 posts from Ory

Filter
Month: Year:
Post Summaries Back to Blog
Customer Identity and Access Management (CIAM) is increasingly crucial as businesses aim to deliver secure and seamless digital experiences while protecting against security breaches and complying with evolving regulations like GDPR and CCPA. CIAM, a specialized branch of Identity and Access Management, focuses on managing external users such as customers and vendors, offering multifaceted benefits like flexible authentication, zero-trust security principles, and federated identity management. Open-source CIAM platforms like Ory provide businesses with the flexibility to customize authentication, scale globally, and ensure compliance without vendor lock-in, offering both self-hosted and managed deployment options. Ory's solutions support passwordless authentication, social logins, and omnichannel identity management, enhancing user convenience while maintaining robust security. The platform also includes advanced features like role-based and attribute-based access control and a Zanzibar-based permission system for precise, real-time authorization. As businesses face challenges in balancing security, scalability, and user experience, Ory's open-source CIAM offers a flexible approach to future-proof customer identity strategies.
Mar 28, 2025 885 words in the original blog post.
OpenAI's rapid expansion, particularly through the success of ChatGPT, underscored the necessity for a robust Customer Identity and Access Management (CIAM) system capable of self-hosting, enhancing user experience, and improving observability. Traditional CIAM solutions fell short in meeting OpenAI's demands for managing sensitive data and user permissions at scale, prompting the company to seek a partner that could support their vision of controlling their identity processes and data. OpenAI collaborated with Ory, utilizing its open-source architecture, along with CockroachDB's distributed database, to achieve the desired performance, resilience, and scalability needed for their operations.
Mar 20, 2025 126 words in the original blog post.
Initially conceived as a student project, Ory Hydra has evolved into a leading open-source OAuth2 server, now powering OpenAI's OAuth2 infrastructure. Originally a Go-based alternative to Keycloak, it shifted focus in 2016 toward developing Ory Fosite, a library for OpenID Connect-compliant OAuth2 servers, which became the cornerstone of Ory Hydra. By removing user management and refining the Login and Consent flow, it allowed seamless integration of OAuth2 and OpenID Connect into existing infrastructures. Over time, Ory Hydra has optimized its performance, achieving benchmarks of thousands of authorization flows per second through strategic use of technologies like PostgreSQL and collaborations with CockroachDB. The project's success is attributed to its clear, scalable design, practical engineering, and strong community engagement, underscoring the importance of simplicity and ongoing optimization in technology development.
Mar 17, 2025 295 words in the original blog post.
BoxyHQ, now part of Ory, emphasizes the importance of security, demonstrated by their recent handling of a disclosed vulnerability in a library they use. The vulnerability involved XML signature verification bypasses that could potentially allow attackers to manipulate data or bypass authentication. Coordinated efforts between BoxyHQ, Alexander Tan, library maintainer Chris Barth, WorkOS, and other vendors led to a swift and responsible patching of the issue, ensuring no customers were affected while reinforcing their multi-tenancy security measures. By implementing strict parsing and validation of XML elements, they addressed the flaws effectively. This incident highlights the significance of robust XML signature verification and the critical role of transparency, collaboration, and rapid remediation in cybersecurity. BoxyHQ's approach involved verifying the issue, coordinating with vendors, deploying interim fixes, and releasing a final patch with guidance, showcasing their commitment to security as a collaborative effort. The company encourages ongoing dialogue about security risks and plans to publish a detailed blog post on the exploit and its mitigation.
Mar 14, 2025 402 words in the original blog post.