Dominick Baier
@leastprivilege.com
π€ 293
π₯ 30
π 74
Advisor & Board Member at Duende Software -
@duendesoftware.com
Supply chain something something... not an issue - all focus back on AI!
add a skeleton here at some point
5 days ago
0
0
1
reposted by
Dominick Baier
Duende Software
8 days ago
We're proud to announce that Duende Software's latest Open Source Sponsorship goes to
#BenchmarkDotNet
! π Check out the full post for details on the project:
duende.link/o55bmd
#dotnet
loading . . .
BenchmarkDotNet - Open Source Sponsorship
Duende Software's latest Open Source Sponsorship goes to BenchmarkDotNet, a benchmarking library for .NET.
https://duende.link/o55bmd
0
1
2
reposted by
Dominick Baier
Maarten Balliauw
15 days ago
Recording of my talk on passkeys in
#aspnetcore
at NDC Copenhagen is up!
#dotnet
Also includes a pointer on how to add passkeys to Razor Pages for folks who aren't on the
#Blazor
train.
www.youtube.com/watch?v=P7eb...
#dotnet
loading . . .
Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core - Maarten Balliauw
YouTube video by NDC Conferences
https://www.youtube.com/watch?v=P7eb3Ig3HO8
0
10
5
reposted by
Dominick Baier
Duende Software
14 days ago
Simplify your identity mess! π€― Learn how a Federation Gateway with Duende IdentityServer orchestrates all your IdPs (Entra ID, Google, SAML) for unified, agile security. Must-read architecture deep dive!
duende.link/8aefizq
#IdentityOrchestration
#SSO
#Security
#dotnet
loading . . .
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.
https://duende.link/8aefizq
0
0
1
reposted by
Dominick Baier
Adam Ralph
11 days ago
My OSS is developed by humans
github.com/adamralph/mi...
loading . . .
GitHub - adamralph/minver: π· Minimalistic versioning using Git tags.
π· Minimalistic versioning using Git tags. Contribute to adamralph/minver development by creating an account on GitHub.
https://github.com/adamralph/minver/
1
16
1
reposted by
Dominick Baier
Duende Software
28 days ago
Stop struggling with diverse identity providers. π A Federation Gateway, such as Duende IdentityServer, is the key to: π Centralized Compliance β‘οΈ Operational Agility π€ Unified User Login
duende.link/8aefizq
#IdentityOrchestration
#SSO
#Security
#dotnet
loading . . .
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.
https://duende.link/8aefizq
0
0
1
reposted by
Dominick Baier
Duende Software
29 days ago
Duende Resolution: Don't Store Tokens in the Browser. π Browser tokens are an XSS risk. Secure your SPAs and Blazor WASM apps with the Duende BFF framework, the best way to handle protocol interactions and token management safely. β‘οΈ
duende.link/bff4b1b
0
1
1
reposted by
Dominick Baier
Duende Software
30 days ago
The Duende Product Insiders program is a private technical channel for partnership. Discuss Identity Strategy, Architecture, and Deployment Nuances directly with Duende experts. Stop guessing, start collaborating. π β‘οΈ
duende.link/discord
loading . . .
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
https://duende.link/discord
0
0
1
reposted by
Dominick Baier
Duende Software
about 1 month ago
For devs who care about identity π¨, Product Insiders get: - Early access to features. - Deep collaboration with Duende leaders. - Direct influence on .NET identity & security. Where standards meet code. Apply:
duende.link/insiders
#DuendeInsiders
#SecurityExperts
loading . . .
Duende Product Insiders
We invite you to join a deeply technical, standards-driven community to help shape the future of .NET security and identity.
https://duende.link/insiders
0
0
1
reposted by
Dominick Baier
Duende Software
about 1 month ago
BFF v4: You can't secure what you can't see. OpenTelemetry is baked right in for end-to-end observability of your auth journey (redirect, token exchange, API calls).
duende.link/bff4b1b
#OpenTelemetry
#Observability
#DuendeBFF
#Diagnostics
#Tracing
loading . . .
Secure frontend apps with the BFF Pattern
Secure frontend apps with the Backend for Frontend (BFF) pattern. Simplify token management and boost security using Duende BFF v4, with multi-frontend support.
https://duende.link/bff4b1b
0
1
2
reposted by
Dominick Baier
Duende Software
about 1 month ago
Your opinion on that tricky DPoP implementation? We want it. Duende Product Insiders is the high-signal, zero-noise channel for advanced .NET identity and security discussions. Join Duende's Product Insiders. β‘οΈ
duende.link/discord
#dotnet
#ZeroNoise
#Identity
loading . . .
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
https://duende.link/discord
0
0
1
reposted by
Dominick Baier
Duende Software
about 2 months ago
Identity developers, lead the way! Join Duende Product Insiders: Directly influence the roadmap, get early feature access, and collaborate with senior experts. Your expertise is needed. Apply today:
duende.link/discord
#DuendeInsiders
#SecurityExperts
loading . . .
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
https://duende.link/discord
0
1
2
reposted by
Dominick Baier
Duende Software
about 2 months ago
π‘οΈ BFF v4: Frontend Security Simplified Frontend devs shouldn't handle tokens or refresh cycles. BFF keeps security on the server, eliminating XSS risks. v4 adds multi-frontend support for operational sanity. Ditch the token burden entirely. β‘οΈ
duende.link/bff4b0b
loading . . .
Duende BFFv4 is now available
Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.
https://duende.link/bff4b0b
0
1
3
reposted by
Dominick Baier
Duende Software
about 2 months ago
Happy Holidays from the Duende Team! π As the year winds down, we want to thank our amazing community for trusting Duende Software to secure your applications. We wish you and yours a wonderful holiday season filled with joy, rest, and peace. Wishing you safe deployments and happy days!
0
3
1
reposted by
Dominick Baier
Duende Software
about 2 months ago
Stop wishing for a feature. Start building it with us. The Duende Product Insiders program is your channel for direct influence on the IdentityServer and BFF roadmap. Join the Insiders:
duende.link/discord
#DuendeSoftware
#IdentityServer
loading . . .
Join the Duende Insiders Discord Server!
Check out the Duende Insiders community on Discord β hang out with 42 other members and enjoy free voice and text chat.
https://duende.link/discord
0
0
1
reposted by
Dominick Baier
Duende Software
about 2 months ago
Stop struggling with diverse identity providers. π A Federation Gateway, such as Duende IdentityServer, is the key to: π Centralized Compliance β‘οΈ Operational Agility π€ Unified User Login
duende.link/8aefizq
#IdentityOrchestration
#SSO
#Security
#dotnet
loading . . .
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.
https://duende.link/8aefizq
0
0
1
reposted by
Dominick Baier
Duende Software
about 2 months ago
Duende BFF v4 is available! Architecturally, this is huge: you can now support multiple frontends from a single, robust backend. Plus, we've integrated OpenTelemetry for seamless end-to-end observability in your identity flow. Simplify your stack:
duendesoftware.com/blog/2025120...
loading . . .
Duende BFFv4 is now available
Duende BFFv4 is now available! Learn about multi-frontend, simplified security, and unlock end-to-end visibility with OpenTelemetry.
https://duendesoftware.com/blog/20251202-duende-bffv4-now-available-multi-frontend-opentelemetry-and-simplified-security
0
3
3
reposted by
Dominick Baier
Barry Dorrans
about 2 months ago
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
loading . . .
Generating SBOMs for .NET apps and NuGet packages with Microsoft.Sbom.Targets
How to use the Microsoft.SBOM.Targets NuGet package to produce a Software Bill of Materials (SBOM) during your release builds.
https://idunno.org/generating-sboms-for-net-apps-and-nuget-packages-with-microsoft-sbom-targets/
1
27
9
reposted by
Dominick Baier
Duende Software
about 2 months ago
Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? It can be a serious security risk! Let's see how to fix this in
#aspnetcore
youtu.be/kSaSb2hBbyk
#dotnet
loading . . .
Understanding the X-Content-Type-Options Header
Ever wondered how browsers determine what kind of content they're displaying? It's usually through the Content-Type header. But what happens when that's missing or incorrect? That's where MIME typeβ¦
https://youtu.be/kSaSb2hBbyk
0
0
2
reposted by
Dominick Baier
Barry Dorrans
2 months ago
Farewell to try .NET a way to run code right in docs that allowed me to introduce a new set of developers and PMs to various security challenges and problems over 10 years. It evolved from running lots of containers in weird isolation setups, all the way through to WASM.
loading . . .
GitHub - dotnet/try: Try .NET provides developers and content authors with tools to create interactive experiences.
Try .NET provides developers and content authors with tools to create interactive experiences. - dotnet/try
https://github.com/dotnet/try
2
22
6
reposted by
Dominick Baier
Erlend Oftedal
about 2 months ago
The call for papers for NDC Security ends tomorrow. Come do your talk in Oslo:
ndcsecurity.com/call-for-pap...
0
3
5
reposted by
Dominick Baier
Duende Software
2 months ago
Let's look into a crucial "defense-in-depth" mechanism: SameSite cookies. Learn how this powerful browser flag adds extra protection against Cross-Site Request Forgery (CSRF) attacks. Strengthen your
#aspnetcore
web applications!
youtu.be/goQlKiynWXU
#dotnet
loading . . .
SameSite Cookies πͺ
Welcome back to Duende Software's web security series! In this video, we're looking into a crucial "defense-in-depth" mechanism: SameSite cookies. Learn how this powerful browser flag can add anβ¦
https://youtu.be/goQlKiynWXU
0
1
3
reposted by
Dominick Baier
Duende Software
2 months ago
Stop struggling with diverse identity providers. π A Federation Gateway, such as Duende IdentityServer, is the key to: π Centralized Compliance β‘οΈ Operational Agility π€ Unified User Login
duende.link/8aefizq
#IdentityOrchestration
#SSO
#Security
#dotnet
loading . . .
Building a Federation Gateway with Duende IdentityServer: Strategies and Considerations for Identity Orchestration
Learn the core benefits of building a federation gateway that brings together Entra ID, Okta, SAML, Auth0 though a centralized authentication provider like DUende IdentityServer.
https://duende.link/8aefizq
0
1
3
reposted by
Dominick Baier
Duende Software
3 months ago
With the .NET 10 LTS released, now is the time to look into upgrading
#IdentityServer4
to Duende IdentityServer! Fix known vulnerabilities and future-proof your security. Get support, FAPI 2.0 compliance, and more.
duende.link/uwo974g
#IdentityServer4
#OAuth2
#OpenIDConnect
#dotnet
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/uwo974g
0
4
2
reposted by
Dominick Baier
Duende Software
3 months ago
In this video, Christian Wenz dives deep into Cross-Site Request Forgery (CSRF), a simple yet devastating attack that has plagued web applications for years. Learn what CSRF is, how it works, and how to defend against it in
#aspnetcore
youtu.be/WUJrKw05YfI
#dotnet
0
0
1
reposted by
Dominick Baier
Duende Software
3 months ago
Claims and scopes describe user information in OpenID Connect. Let's see how Duende IdentityServer handles consent, different client types, required vs. optional scopes, and what happens when a client doesn't get everything it asked for.
duende.link/97aeqlj
π
#dotnet
#aspnetcore
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/97aeqlj
0
2
7
reposted by
Dominick Baier
Duende Software
4 months ago
Adding .NET 10 Passkey Support to Duende IdentityServer π
duende.link/berqe86
Learn how to add
#dotnet
10 passkey support to a non-Blazor project such as MVC or Razor Pages.
#security
#aspnetcore
#identity
#webauthn
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/berqe86
0
1
5
reposted by
Dominick Baier
Duende Software
4 months ago
The server's origin is used to generate passkey credentials, making them resistant to phishing. A credential signed for one app can't be used elsewhere. What about subdomains? Or multiple domains? In this post, we'll explore some options.
duende.link/igeq87f
#dotnet
#security
#passkeys
#webauthn
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/igeq87f
0
2
3
reposted by
Dominick Baier
Maarten Balliauw
4 months ago
The upcoming release of
#dotnet
10 comes with built-in passkey support. Had good fun digging into the new
#Blazor
project template and how it adds secure authentication using passkeys.
duende.link/37egw9f
#aspnetcore
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/37egw9f
0
8
6
reposted by
Dominick Baier
Sustainsys
4 months ago
Duende Software's legendary training on Identity and Access Management was originally created by Dominick Baier and Brock Allen. We're offering the training online/remotely as 6 half-day blocks the first two weeks of November. Read more and sign up at
sustainsys.com/training
loading . . .
Training Information
https://sustainsys.com/training
0
0
2
reposted by
Dominick Baier
Duende Software
4 months ago
Say goodbye β to passwords, and hello π to secure, phishing-resistant logins: passkey credentials. Part 1 of our 4-part blog series covers password and authentication evolution. Longread ahead! π
duende.link/p455k3y
#passkeys
#webauthn
#dotnet
#security
#aspnetcore
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/p455k3y
0
6
4
reposted by
Dominick Baier
Maarten Balliauw
4 months ago
I'm hiring! Looking for an
#aspnetcore
dev, ideally with identity/oidc experience. Role is support, tech presales, advisory, docs, ... East coast US ideally for timezone overlap in the team Small team and company, big ambition. Reach out if you're interested!
duendesoftware.com/careers/cust...
loading . . .
Customer Success Engineer
Duende software looking to fill Customer Success Engineer position
https://duendesoftware.com/careers/customer-success-engineer
1
11
13
reposted by
Dominick Baier
Duende Software
4 months ago
Discover a key update in
#dotnet
10 that improves local development! π₯ π Our latest blog post explains how a new TLS certificate and unique local domains can solve cookie conflicts and better mimic production environments.
duende.link/arbgu89
#aspnetcore
#security
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/arbgu89
0
3
3
reposted by
Dominick Baier
Barry Dorrans
5 months ago
lol the conclusions are so so wrong
medium.com/c-sharp-prog...
loading . . .
They Laughed at My βNo JWTβ RuleβββUntil Our Breach PostβMortem Went Viral (for the Right Reasons)
Everyone told us we needed OAuth2 and signed tokens. We used mutual TLS, internal claims binding, and a little-known header signing trickβ¦
https://medium.com/c-sharp-programming/they-laughed-at-my-no-jwt-rule-until-our-breach-post-mortem-went-viral-for-the-right-reasons-3e427244463a
2
4
2
reposted by
Dominick Baier
Aaron Parecki
5 months ago
The IETF OAuth Working Group has adopted the Identity Assertion Authorization Grant specification!
datatracker.ietf.org/doc/draft-ie...
This is the basis of Cross App Access (XAA), providing IT admins better visibility and control by configuring the app-to-app connections in their enterprise IdP.
loading . . .
Identity Assertion Authorization Grant
This specification provides a mechanism for an application to use an identity assertion to obtain an access token for a third-party API by coordinating through a common enterprise identity provider us...
https://datatracker.ietf.org/doc/draft-ietf-oauth-identity-assertion-authz-grant/
1
6
4
reposted by
Dominick Baier
Duende Software
5 months ago
Don't miss our livestream tomorrow with Microsoft .NET MVP Tore Nestenius! Demystifying Authentication in
#aspnetcore
Core. π September 18, 2025 π 10:00 EST / 16:00 CEST Register now:
duendesoftware.com/webinars/dem...
#security
#identity
0
1
1
reposted by
Dominick Baier
Duende Software
5 months ago
Brace yourself, wΜΆiΜΆnΜΆtΜΆeΜΆrΜΆ
#dotnet
10 is coming! βοΈ Let's look at the new capabilities and features we are excited about for the upcoming .NET release in November. Expect passkeys,
#opentelemetry
additions,TLS for *.localhost, and more. π
duende.link/qet4wp9
#aspnetcore
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/qet4wp9
0
4
5
reposted by
Dominick Baier
Joe DeCock
5 months ago
If you missed my live stream, don't worryβthe internet will keep it available forever. And if I said anything dumb, that's also never going away.
add a skeleton here at some point
0
1
1
reposted by
Dominick Baier
Duende Software
5 months ago
Watch the recording of our
#IdentityServer
7.3 launch!
duendesoftware.com/webinars/due...
Joe DeCock covers new templates, and looks at setting up your environment for the FAPI 2.0 security profile and conformance tests.
#dotnet
#security
#identity
0
1
3
reposted by
Dominick Baier
Duende Software
5 months ago
What are Best Practices of Web Application Security in 2025? This post focuses on key security and authentication flows using OAuth 2.0 and OpenID Connect, flows to avoid, security measures to implement, and IETF Best Current Practices.
duende.link/iyqe3fk
#security
#dotnet
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/iyqe3fk
0
3
3
reposted by
Dominick Baier
Duende Software
5 months ago
We'll host a livestream with Tore Nestenius! πΉ Authentication has many concepts and moving parts. In this session, we'll clarify how authentication in
#aspnetcore
works. π September 18, 2025 π 10:00 EST / 16:00 CEST
duendesoftware.com/webinars/dem...
#dotnet
#security
loading . . .
Demystifying authentication in ASP.NET Core
Demystify ASP.NET Core authentication. Learn key concepts like schemas, handlers, and ClaimsPrincipal in this hands-on deep dive with .NET MVP Tore Nestenius.
https://duendesoftware.com/webinars/demystifying-authentication-asp-dot-net-core
0
1
1
reposted by
Dominick Baier
Duende Software
5 months ago
HttpClient is at the heart of many projects. DelegatingHandlers let you intercept and modify requests and responses, extending base functionality. In this blog post, we'll look at DelegatingHandler and how it can make HttpClient even more powerful! πͺ
duende.link/78qe4kj
#dotnet
#aspnetcore
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duendesoftware.com/blog/20250902-dotnet-httpclient-and-delegating-handlers?utm_campaign=content&utm_medium=social&utm_source=social
0
3
5
reposted by
Dominick Baier
Wesley Cabus
5 months ago
We're hiring! At
@duendesoftware.com
, we're looking for someone to join our Customer Success team. It's a 100% remote position but we are looking for someone based in the US East Coast region for time zone reasons. If you're interested, visit
duendesoftware.com/careers/cust...
for details!
#hiring
loading . . .
Customer Success Engineer
Duende software looking to fill Customer Success Engineer position
https://duendesoftware.com/careers/customer-success-engineer
0
0
6
reposted by
Dominick Baier
Yves Reynhout
6 months ago
π
0
6
2
reposted by
Dominick Baier
Duende Software
6 months ago
Meet Duende
#IdentityServer
v7.3! This new release includes: π Enhanced security & future proofing with FAPI 2.0 support π Quick start templates to accelerate development. π And more.... Release blog here β‘οΈ
duende.link/is73b0b
#dotnet
#security
#identity
0
3
3
reposted by
Dominick Baier
Duende Software
6 months ago
External identity providers in
#aspnetcore
In this post, we cover initial setup (with Google), the connection between external and cookie authentication, and discusses why alternatives might be better for production apps.
duende.link/q24tubs
#security
#identity
#dotnet
loading . . .
Duende Software - Identity and Access Management for .NET
We help companies using .NET to build identity and access control solutions for modern applications.
https://duende.link/q24tubs
0
1
2
reposted by
Dominick Baier
Duende Software
6 months ago
Meet Duende
#IdentityServer
v7.3! This new release includes: π Enhanced security & future proofing with FAPI 2.0 support π Quick start templates to accelerate development. π And more.... Release blog here β‘οΈ
duende.link/is73b0b
#dotnet
#security
#identity
0
6
5
reposted by
Dominick Baier
Duende Software
6 months ago
We're at
#kcdc2025
Stop by and register to win a NASA Artemis Space Launch System LEGO set. Or just say hello and meet the Duende team. Learn more about our newly released Duende
#IdentityServer
v7.3 with FAPI 2.0.
#dotnet
#security
#identity
1
4
1
reposted by
Dominick Baier
Duende Software
6 months ago
Livestream Launch Event: Duende
#IdentityServer
7.3 with FAPI 2.0 + New Quick Start Templates. ποΈ August 21, 2025 π 10 EST / 16:00 CEST / 14:00 UTC π§βπ¦° Speaker: Joe DeCock Clear your calendars and register here β‘οΈ
duende.link/is73w0b
#dotnet
#security
#identity
0
2
2
reposted by
Dominick Baier
Khalid-a-tron β‘
6 months ago
Are you worried your
#dotnet
#security
could be more secure? Join us for a
#livestream
on August 21st, 2025, to discuss FAPI 2.0, its relation to
#oauth
and
#openid
, and how to harden your security posture, with our guest, Joe βMr. Identityβ DeCock. If nothing else, join us with what is a [β¦]
loading . . .
Original post on mastodon.social
https://mastodon.social/@khalidabuhakmeh/115011039669273848
0
1
4
Load more
feeds!
log in