bala's random rumblings
Archives Slides Talks

bala’s random rumblings🌱

echo $THOUGHTS > /dev/blog

Jun 5, 2025

NIST SP 800-63C-4: How Identity Crosses Trust Boundaries

Every time a user clicks “Sign in with Google” or gets SSO access to a third-party app from a corporate IdP, identity crosses a trust boundary. Identity proofing happened somewhere, authentication happened somewhere else, and now another system needs to rely on that result.

Continue Reading

Mar 15, 2025

NIST SP 800-63B-4: What “Strong Authentication” Actually Means

NIST SP 800-63B-4 is the authentication volume of the 800-63-4 suite. It defines exactly what authenticator types qualify at each assurance level, what phishing resistance actually requires, and what your session and recovery policies need to look like.

Continue Reading

Jan 19, 2025

Building Multi-Tenant SaaS Applications

In this blog, I’m summarizing key concepts and ideas i take way from book ā€œBuilding Multi-Tenant SaaS Architecturesā€ by Tod Golding, which I started reading while working on Tenant Management System at Money Forward.

Continue Reading

Jan 5, 2025

NIST SP 800-63A-4: How to Prove Someone Is Who They Say They Are

NIST SP 800-63A-4 is the identity proofing volume of the 800-63-4 suite. It defines exactly what “verified identity” means at each assurance level, what evidence qualifies, how to handle the cases that break the happy path, and what your fraud program needs to look like.

Continue Reading

  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »
  • »»

Bala

An ID Developer at Money Forward, Tokyo. Designing secure authentication solutions using OAuth2.0, OpenID, SAML, and Passkeys. Experienced in microservices, DevOps, and SRE optimizations. Passionate about building robust, secure identity systems. LinkedIn.

Story logo

© 2026 bala