I build things; I write code; I void warranties. My latest book is Learning Digital Identity from O'Reilly amzn.to/43WzwDC #identity #zerotrust

Joined March 2007
1,151 Photos and videos
Pinned Tweet
27 Feb 2024
If you're looking for a high-level introduction to the core ideas in digital identity and how digital identity is foundational to the nature of the relationships we create online, check out my book, Learning Digital Identity from @OReillyMedia amzn.to/43WzwDC
3
13
55
3,361
Phil Windley retweeted
I don't typically get this philosophical, but did with this one - Opinion: Moral clarity still mattershttps://www.deseret.com/opinion/2026/06/11/why-moral-clarity-still-matters/
1
1
3
156
Apparently @citi really hates when I use their card at @HomeDepot. Every time I order online, they pop up something asking me to approve the purchase on my Citi app on my phone. Way easier to use some other card.
4
1
1
524
But...but...but...SECURITY!!! I get it. Don't care. I expect you to make my purchases secure without inconveniencing me. Unreasonable? Maybe. Don't care.
121
Cleaning up manifold-api as a prerequisite for the spring conversational interface capstone turned into a complete platform update: Pico Engine 1.0 compatibility, automated bootstrap, centralized notifications, and a Docker-based integration test harness. Once the platform was solid, the old temperature-network had an obvious new home inside Manifold's community framework, so I rewrote it too as an example of how Manifold can be a framework for pico networks. » Manifold API and Sensor Network: Two New Repos windley.com/archives/2026/06…
1
85
If federal law is going to prohibit me from bringing beverages through security then it should also prohibit airports from establishing effective Pepsi monopolies.
6
268
Phil Windley retweeted
Most teams are building custom identity for their AI agents. Most teams should stop. That's the talk @sarah_cecc and I gave at @fwdcloudsec — now on YouTube. The standards to do this right mostly already exist. We just have to compose them. youtube.com/watch?v=wWoA0Ct9…
3
2
414
Phil Windley retweeted
Employees who already spend their time working on things that don't matter will not suddenly become high impact because of AI. AI can be an amplifier. Whether that's good, bad, or neutral depends on the person.
3
1
8
580
Phil Windley retweeted
🪪 The interesting part isn’t just the scale — it’s how much high-value identity data was sitting behind a single successfully manipulated employee account.
1
1
2
106
Picos are a natural substrate for AI agents because they already have the properties that matter most: persistent identity, owned state, and event-driven behavior. The integration path starts with something simple — a webhook — and leads somewhere important. » AI Integration in Picos Starts with Events windley.com/archives/2026/06…
1
1
1
132
Occasionally, someone uses my backup email address to sign up for an account. I presume they've mistyped it or left off a letter. The problem (for them) is that now I can get into their account. Usually, they recognize the problem and fix it. But sometimes they don't. Which means I can use password reset to take over their account. Always make sure you get a signup email from the service you registered at.
1
123
Is there any way to get an @ecobee API key for @home_assistant integration since Ecobee isn't accepting developers? I want to put my thermostats in HA. @hass_devs
1
178
Turns out, you don’t need an API key if you use the username/password, but you have to disable 2FA temporarily. But the error message doesn’t say that, it complains about the APi key being missing.
107
287 attendees called 158 sessions over the three days of IIW. Here's my report. » Internet Identity Workshop XLII Report windley.com/archives/2026/06…
1
235
Not sure this is the best name. I thought it was literally targetting emissions from real beehives. I get it now...we're the Beehive state...but I didn't just reading the title. » Beehive Emission Reduction Plan deq.utah.gov/daq/beehive-emi…

1
85
I'm about to cancel my @REI credit card because of @CapitalOne's hot mess of an authentication system. Almost twice a month they lock my account because of failed sign in attempts. They inconvenience me over their security problems. No one else does this. Start using passkeys and fix the problem!
1
1
241
I spend more time logging into @capitalone to fix this problem than I *ever* do using their website.
3
172
I've never gotten @capitalone's passkey to work from @1Password. @Intuit's and many others work flawlessly.
1
117
I'm excited to share that the final 3 chapters and the last appendix for Authorization in Action are now available on the Manning Early Access Program (MEAP). They are: 17 AI in Policy Practice 18 Authorization for AI Agents 19 Authorization as Strategy C Cedar Authorization for OpenClaw Agents manning.com/books/authorizat…
1
3
100