October 2025 Summaries
6 posts from Ory
Filter
Month:
Year:
Post Summaries
Back to Blog
A recent 60 Minutes segment titled "The China Hack" highlights the vulnerabilities in U.S. critical infrastructure due to cyberattacks allegedly connected to the People’s Republic of China, which have targeted not only major entities but also small local utilities, such as a town in Massachusetts. The report emphasizes the growing importance of identity protection as adversaries often penetrate networks by stealing login credentials and masquerading as legitimate users. This underscores the need for robust identity and access management (IAM) solutions, as traditional perimeter security measures are insufficient against such threats. Companies like Ory advocate for treating identity as the new perimeter, stressing the necessity of continuous verification and zero-trust models to secure both human and non-human identities within complex systems. The segment serves as a wake-up call for organizations to invest in scalable and reliable identity infrastructure to prevent adversaries from weaponizing trusted systems, thereby safeguarding essential services like water and power supplies.
Oct 27, 2025
1,128 words in the original blog post.
WebAuthn and passkeys offer a modern approach to user authentication by eliminating the need for traditional passwords and providing a more secure, phishing-resistant environment through public-key cryptography. While WebAuthn serves as the protocol and API enabling secure login via browsers, passkeys enhance user experience by allowing seamless cross-device login and biometric authentication. However, implementing these technologies at scale involves navigating several challenges, including account recovery, cross-device compatibility, migration from legacy systems, and compliance with regulatory requirements. Ory provides a strategic approach to optimizing the user experience for passkey-based authentication, addressing issues such as lifecycle management and fallback strategies. The adoption of passkeys requires careful planning around domain stability, user education, and comprehensive testing across different devices and platforms to ensure a successful transition to passwordless authentication.
Oct 24, 2025
1,302 words in the original blog post.
The identity landscape is undergoing a significant transformation as web browsers phase out third-party cookies, undermining traditional social login methods and increasing the friction of outdated login systems, which translates to revenue loss for businesses. Federated Credential Management (FedCM) emerges as a privacy-first solution that enhances user experience and data quality without the drawbacks of third-party cookies. Axel Springer, a major European media company, experienced a remarkable 1,500% increase in registrations after implementing FedCM, which streamlined the sign-in process and provided verified user data, leading to lower costs associated with cleaning up fake accounts. FedCM's integration into native browser APIs eliminates cumbersome redirects and pop-ups, offering a seamless user experience while ensuring business stability and future-proofing against further privacy changes. The shift away from third-party cookies presents an opportunity for businesses to foster more meaningful user relationships and secure growth by adopting privacy-first identity solutions like FedCM.
Oct 22, 2025
712 words in the original blog post.
As AI platforms like ChatGPT, Google's Gemini, and Meta AI rapidly expand their user bases and integrate with major brands such as Uber and Walmart, a new paradigm of "agentic commerce" is emerging, where AI systems autonomously conduct transactions on behalf of users. This shift presents significant challenges in identity and authorization management, as traditional models are ill-equipped to handle the complexities of AI agents making decisions based on natural language inputs. Industry experts highlight the urgent need for rethinking identity infrastructure to treat AI agents as distinct entities with their own permissions, employing context-aware and relationship-based access control. The lack of standardized protocols across competing AI platforms exacerbates the risk of security breaches, as users often lose track of delegated permissions. The development and adoption of open standards like the Model Context Protocol (MCP) are pivotal in ensuring secure interoperability, but comprehensive identity and authorization frameworks are still lacking. Companies that proactively implement advanced identity management systems will not only enhance security but also gain a competitive advantage in the evolving digital commerce landscape, as the race to establish safe, scalable agentic commerce continues.
Oct 16, 2025
1,703 words in the original blog post.
As the digital economy rapidly evolves, organizations face the challenge of adapting to a new wave of AI-driven customers, including AI agents, Machine Customers, and Custobots, which are poised to outnumber human shoppers. This shift necessitates a rethinking of Identity and Access Management (IAM) systems, which were traditionally designed for human users, to accommodate the unique needs of AI entities. These non-human customers require advanced authentication and authorization solutions that provide machine-to-machine authentication, granular authorization, and high-volume, low-latency performance. With AI agents capable of executing thousands of transactions per minute, IAM becomes a crucial aspect of transaction infrastructure. Ory offers a solution tailored for this future, providing scalable, flexible, and secure identity infrastructure that supports modern cloud architectures and API-first, machine-to-machine authentication patterns. As AI-driven commerce becomes more prevalent, businesses must promptly reassess their identity systems to capitalize on the opportunities presented by this new digital landscape.
Oct 08, 2025
598 words in the original blog post.
AI agents, which are autonomous software entities capable of planning, reasoning, and acting without direct human intervention, are increasingly being integrated into enterprise operations such as supply chain management and financial trading. However, this rise presents a significant challenge in terms of accountability and security, as traditional Identity and Access Management (IAM) systems are not equipped to handle the unique requirements of AI agents. To address these issues, experts are advocating for the creation of digital identities for AI agents, akin to digital "personhood." This concept is not about endowing AI with consciousness but rather ensuring that each agent has a traceable and verifiable identity, which is essential for auditing, compliance, security, and governance. By assigning digital identities, organizations can effectively monitor and restrict AI agent activities, ensuring they operate within designated parameters and comply with internal and regulatory policies. As enterprises scale their use of AI, establishing a robust digital identity framework for AI agents will be crucial for maintaining security and fostering trust in autonomous operations.
Oct 03, 2025
680 words in the original blog post.