NIST Finalizes Guidelines on Protecting Online Identity and Access Tokens From Misuse

https://www.nist.gov/themes/custom/nist_www/img/homepage/nist_mark.png
  • A newly finalized report can help cloud service providers and their customers better protect identity and access tokens, which are widely used when accessing online applications.
  • In the hands of an adversary, tokens can be dangerous, and the publication is designed to help organizations take effective steps to avoid exposing them to attackers.
  • The report authors have modified and expanded the publication in response to public feedback on the December 2025 draft version.

When you sign in to an online service like webmail, behind the scenes is often a token — a snippet of information identifying you and what online resources you are permitted to use, such as your inbox, contacts or other potentially sensitive information. Keeping these tokens safe is critical for protecting against unauthorized access, and it’s the goal of a newly finalized publication from the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure...

Copyright of this story solely belongs to www.nist.gov. To see the full text click HERE