Zero Security Theatre
Evidence library
These sources support or challenge the work. Each note says what the source can establish, and contrary evidence stays in the library.
Standard
NIST SP 800-63, digital identity guidelines
Authenticator assurance levels, including the properties that make a credential resistant to phishing.
Used by Human error without human blame
Advisory
CISA guidance on phishing-resistant multifactor authentication
Shows how the credential itself can block phishing even when a message fools the user.
Used by Human error without human blame
Advisory
CISA Secure by Design
Places responsibility for safe defaults with the supplier, which is the vendor-side form of this area's design argument.
Used by Vendor and supply-chain resilience, Human error without human blame
