Alvaro Navarro

No More Post-its: Boost your login security with APIs

Is your two-factor authentication vulnerable to SIM swap fraud? Learn how to use APIs to detect suspicious activity before it's too late.

No More Post-its: Boost your login security with APIs
#1about 5 minutes

Understanding the vulnerabilities of password-based authentication

Passwords are a major security risk because they are easily forgotten, guessed, or cracked, as demonstrated by common password lists and data breaches.

#2about 2 minutes

Implementing two-factor authentication with the Verify API

Add an extra layer of security by implementing two-factor authentication (2FA) using one-time passwords (OTP) delivered via SMS, voice, or other channels with an API.

#3about 2 minutes

Verifying phone numbers and preventing SIM swap attacks

Ensure the phone number receiving an OTP is valid and protect against SIM swap fraud by checking for recent SIM card changes using dedicated APIs.

#4about 2 minutes

Creating a seamless login with silent authentication

Authenticate users frictionlessly in the background by verifying their identity through their mobile data connection and SIM card without requiring manual input.

#5about 2 minutes

Using biometrics and location as authentication factors

Incorporate advanced authentication factors like biometrics for "something you are" and geolocation for "somewhere you are" to further enhance security.

#6about 2 minutes

A summary of APIs for multi-layered security

A recap of the various APIs available to build a robust, multi-layered authentication system covering what you know, have, are, and where you are.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
CH
Chris Heilmann
The top 200 passwords of 2024 can be cracked in less than a second
Passwords are a pain and with biometric logins, passkeys and other two factor authentication methods should be a thing of the past. In reality, though, a lot of systems still use username and password as the only security measure and users choose al...
The top 200 passwords of 2024 can be cracked in less than a second
DC
Daniel Cranney
Dev Digest 198: 30 years of JS, In-Browser AI, How Attackers Abuse GenAI
Inside last week’s Dev Digest 198 . 🎂 30 years of JavaScript ⏰ How long is a JavaScript second 💻 Clean code in Angular 🤦‍♂️ AI makes different mistakes than humans 👨‍💻 In-browser and offline AI 🟠 Undocumented Hacker News features 🐋 DeepSeek censored...
Dev Digest 198: 30 years of JS, In-Browser AI, How Attackers Abuse GenAI
DC
Daniel Cranney
Dev Digest 167: Open Source AI, Passwordless Microsoft and Vibe Coding
Inside last week’s Dev Digest 167 . 🖼️ Is vibe coding killing creativity? 🌳 Is ChatGPT not as bad for the environment as we think? ⚠️ 95% of AppSec fixes don’t reduce risks 🔑 Microsoft going passwordless 🧠 How to detect memory leaks in your apps 🟨 V...
Dev Digest 167: Open Source AI, Passwordless Microsoft and Vibe Coding
DC
Daniel Cranney
Security Basics for Vibe Coders
Vibe coding has become a popular trend in the tech world. With so many tools now available for both developers and non-developers, it’s easier than ever to build projects using natural language, in some cases without touching a line of code along the...
Security Basics for Vibe Coders

From learning to earning

Jobs that call for the skills explored in this talk.

Senior SDET

Senior SDET

Vonage
Barcelona, Spain

API
REST
Python
Vue.js
Kotlin
+4