Security Key
Authentication
Authenticator (platform or roaming) performing public-key challenge-response for authentication.
Glossary
Plain-language explanations for encryption, tracking, compliance, and security concepts.
Authentication
Authenticator (platform or roaming) performing public-key challenge-response for authentication.
Authentication
Authentication factor/token used to assert identity; may be hardware-backed or software-based.
Security
Mnemonic used to derive wallet keys; effectively a master recovery secret.
Security
Deployment model where the operator controls infrastructure, data storage, and configuration.
Security
Operational practice of hosting and administering services under your own control.
Privacy
Decentralized identity model where users hold verifiable credentials and control disclosure.
Privacy
Higher-risk personal data categories (e.g., health, biometrics, precise location) requiring enhanced safeguards.
Session Management
Cookie storing a session identifier; security depends on flags (Secure, HttpOnly, SameSite) and rotation.
Threats
Unauthorized reuse of a valid session identifier.
Security
Lifecycle control of authentication sessions and tokens.
Security
Unmanaged or unauthorized systems/services used outside official governance and controls.
Network Privacy
Multi-tenant IP usage via NAT or shared egress.
Security
Security Information and Event Management platform aggregating logs, correlating events, and generating alerts.
Threats
Account takeover technique involving fraudulent SIM reassignment at a carrier to intercept calls/SMS.
Authentication
Authentication scheme where one identity session grants access to multiple relying parties via tokens.
Security
Self-executing program deployed to a blockchain, executed by the network.
Security
Operational function responsible for continuous monitoring, detection, triage, and incident response.
Threats
Psychological manipulation tactics used to elicit secrets, actions, or access from targets.
Security
Upstream components, dependencies, build pipelines, and distribution channels involved in producing and delivering software.
Threats
Targeted social engineering using personalized context.
Security
Sender Policy Framework: DNS-based authorization of sending IPs/hosts for a domain; used in anti-spoofing.
Network Privacy
Policy-based routing around a VPN gateway.
Threats
Covert data collection malware.
Encryption
Legacy transport security protocol family.