Identity

When Fraud Detection Works Too Late

The Wall Street Journal’s investigation into Polymarket, by Katherine Long, Caitlin Ostroff and Neil Mehta, is a useful case study in where fraud controls sit rather than how well any individual control performs. One detail stands out. At the peak of a February attack, according to the Journal, Polymarket’s payment processor was rejecting more than 80% of the deposits it handled as fraudulent, against an industry norm of roughly 1%. The processor appears to have been working well at the point in the stack where it had visibility. The larger problem was how much bad activity had already reached that point.

Learn more →

Inherited Flaws: Why the Inbox is the Master Credential

The security industry has spent the last decade meticulously fortifying the application perimeter. Organizations layered biometric authentication, hardware-backed credentials, behavioral analytics, adaptive risk scoring, device intelligence, passkeys, and increasingly sophisticated identity orchestration into login and recovery workflows, all in pursuit of reducing dependence on static credentials and limiting unauthorized access at the application layer. Yet, as organizations built these complex, frictionless entryways, they largely ignored the structural foundation upon which they rest.

Learn more →