1. Tokens & JWTs advanced

    A team is designing token-based authentication for a distributed system. What are the significant design decisions, and which common JWT choices cause problems later?

    2 min answer jwttokensrevocationsessions
  2. Tokens & JWTs advanced

    After a routine signing key rotation, roughly 3% of API requests start failing with 401s. The rate decays over about ten minutes and returns on the next rotation. Tokens look valid and clocks are synchronised. What is happening?

    3 min answer jwtjwkskey rotationcaching
  3. Tokens & JWTs advanced

    An identity provider issues tokens that applications validate locally without a network call. What does that buy, and what is the necessary consequence for revocation?

    2 min answer clerkauth0jwtrevocation
  4. Tokens & JWTs advanced

    Your JWT-based auth means a fired employee keeps access for 15 minutes after their account is disabled. Security says that is unacceptable. What are the options?

    2 min answer jwtrevocationtokenstradeoffs
  5. Tokens & JWTs intermediate

    Your JWTs last one hour. An employee is dismissed. Security asks why they still had system access for 45 minutes. Explain and fix.

    2 min answer jwtrevocationsessions
  6. Zero Trust advanced

    A board mandate says "implement zero trust in twelve months". What do you actually do, in what order?

    2 min answer zero-trustsequencingpragmatism
  7. Zero Trust advanced

    A digital bank adopts zero trust. What actually changes in the architecture, and what is commonly mistaken for zero trust?

    2 min answer jupiterzero-trustidentitymtls
  8. Zero Trust advanced

    A platform replaces network-level trust with per-request authorisation - every call to every internal service is checked against a central policy service. Security is satisfied. What has the platform given up, and when does that bill arrive?

    3 min answer zero trustauthorizationavailabilitylatency
  9. Zero Trust advanced

    An organisation decides to adopt zero trust. What does it actually mean architecturally, what is the realistic implementation order, and where does it fail?

    3 min answer zero-trustidentitymtlsnetwork-security
  10. Zero Trust advanced

    An organisation replaces its VPN with an identity-aware access model. What actually has to change beyond the network, and where do these programmes stall?

    2 min answer zero-trustidentitydevice-trustmigration
  11. Zero Trust advanced

    How would you assess your estate's exposure to lateral movement, in a way that produces actionable findings?

    2 min answer securityblast-radiusassessment