Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
Engineering archive

AmbiSecure engineering writing — 2017 through today.

These pieces trace how we have thought about FIDO, smart cards, MFA, transit, and IoT security across nearly a decade of engineering. They sit alongside our newer cornerstone writing — the field has evolved, our thinking has evolved, and where a piece is older we link forward to current coverage of the same topic.

Showing 24 earlier engineering entries, newest first. For the latest engineering writing, see the main blog — its newest 24 posts sit on page 1 and the older modern posts on page 2.

What is in the archive?

2021-08-19

Common Misconceptions about Two-Factor Authentication

Unpacks the most common misconceptions about two-factor authentication — what 2FA actually defends against, where SMS-based codes fall short, and why hardware-rooted second factors hold up under credential-theft attacks.

Read article → MFA · Cybersecurity
2021-08-19

Single Sign-On Vs. Multi-Factor Authentication

Compares single sign-on with multi-factor authentication — when each model fits, where they overlap, and how SSO + MFA combine for enterprise identity.

Read article → MFA · Identity
2021-08-19

Multi-factor Authentication in Government Sector

Why government identity programmes are adopting multi-factor authentication, how MFA holds up against phishing and credential theft, and where hardware-rooted authenticators sit in the stack.

Read article → MFA · Government Identity
2021-08-05

Cyber Attacks in India – Part 3

Part three of a three-part analysis of major cyber attacks in India — closing the series with systemic gaps in incident response, identity hygiene, and hardware-rooted authentication adoption.

Read article → Cyber Threats
2021-07-28

Cyber Attacks in India – Part 2

Part two of a three-part analysis of major cyber attacks in India — the attack patterns, the identity weaknesses they exploited, and what enterprise authentication posture would have stopped them.

Read article → Cyber Threats
2021-07-28

Cyber Attacks in India

Part one of a three-part analysis of major cyber attacks in India and what they reveal about systemic gaps in online identity, authentication, and incident response.

Read article → Cyber Threats
2021-07-06

Enterprise Security Threats

A field overview of enterprise security threats in the cloud era — how the digital attack surface expands as organisations adopt new platforms, and where hardware-rooted identity narrows it.

Read article → Cyber Threats · Enterprise MFA
2021-06-01

What is Passwordless Authentication?

A primer on passwordless authentication — what it actually means, how FIDO and biometrics replace shared secrets, and why hardware-bound credentials sit at the centre of the model.

Read article → Passwordless · FIDO
2021-06-01

Is Passwordless the future?

Examines whether passwordless authentication can scale beyond pilots — the standards, attack-surface trade-offs, and operational realities that decide its trajectory.

Read article → Passwordless
2021-06-01

SMS-based OTP Authentication and Its Disadvantages

Why SMS-based one-time passwords are no longer a defensible second factor — SIM-swap attacks, SS7 weaknesses, phishing-prone OTP relay, and the hardware-rooted alternatives.

Read article → MFA · Cyber Threats
2021-01-28

ePassport and How will chip-based e-Passports work

How chip-based ePassports work in practice — the BAC / PACE access protocols, the CSCA / DSC / PKD trust chain, and the role of the secure element inside the document.

Read article → Smart Cards · Government Identity · ePassport
2021-01-28

ePassport and Its Application

How biometric passports work in practice — chip-based identity, border-control architecture, and the standards stack that keeps the issuer chain trustworthy.

Read article → Smart Cards · Government Identity · ePassport
2020-12-15

An Introduction to Java Card Technology

An introduction to JavaCard — how Java-based applets run securely on smart cards and other small-memory secure elements, why the JavaCard runtime model exists, and what it enables for FIDO, PIV, and ePassport applets.

Read article → JavaCard · Smart Cards
2020-12-15

Fast Identity Online (FIDO)

A primer on FIDO (Fast Identity Online) and the Universal Second Factor model — how FIDO replaces shared secrets with hardware-bound credentials and why it changes the phishing-resistance baseline.

Read article → FIDO · Passwordless
2020-08-28

Understanding EMV certification In Public Transportation

A practical look at EMV certification in public transport — which certifications apply, the roles of acquirer, scheme, terminal vendor, and transit authority, and the typical timeline from prototype to revenue service.

Read article → Transit · Smart Cards
2020-07-30

Workplace Security — How Biometrics Is the Key to the New Normal

How workplace biometrics layer additional security onto existing authentication methods — face / fingerprint / palm, the privacy controls that keep them defensible, and where they sit alongside FIDO and MFA.

Read article → Biometrics · Enterprise MFA
2020-06-29

Consumer Biometrics in the Data Privacy Age

How organisations can deploy biometric authentication while still meeting modern privacy expectations — match-on-device versus match-on-server, template storage, and the regulatory shape of consumer biometric data.

Read article → Biometrics · Privacy
2020-06-08

Securing your IIoT infrastructure

Why industrial IoT infrastructure remains a high-value target — the markets driving adoption, the trust gaps in legacy OT, and how hardware-rooted device identity tightens them.

Read article → IoT Security
2020-05-26

Public Transport Ticketing System (Part-3)

Part three of a 2020 survey of public transport ticketing — how fare collection worked in Singapore, Indonesia and Hong Kong.

Read article → Transit
2020-05-18

Public Transport Ticketing System (Part-2)

Part two of a 2020 survey of public transport ticketing — how fare collection worked in the United Kingdom, Germany, Russia, Brazil and Mexico.

Read article → Transit
2020-05-12

Public Transport Ticketing System (Part-1)

First of three articles on automated fare collection — a comparative look at ticketing architectures across advanced economies and large transit networks in Asia.

Read article → Transit
2020-04-27

Challenges to IoT Security (Part 2)

Second of a 2020 two-part look at IoT security — further challenges: infrequent firmware updates, small-scale attacks, autonomous systems and user privacy.

Read article → IoT Security
2020-04-20

Challenges to IoT Security (Part 1)

First of a two-part look at IoT security — how billions of devices communicate with enterprise systems, where the resulting attack surface sits, and the trust anchors that contain it.

Read article → IoT Security

Editorial classification — how Ambimat / AmbiSecure / eSIM split content.

This archive lists earlier AmbiSecure-themed engineering pieces. Adjacent topics — cold-chain logistics, hardware-startup notes, UWB rollout, and general electronics — live on the parent Ambimat site, and LPWAN, 5G security, and cellular WAN pieces live on the SIMAuth site. Every URL still resolves to the right property.

Modern blog

Frequently asked questions

What is in the AmbiSecure engineering archive?

Earlier AmbiSecure engineering posts from 2017–2025, kept for reference and clearly labelled as archive content.

Is archive content still accurate?

Archive entries reflect thinking at the time of writing and link forward to current coverage where it exists; newer posts supersede them where topics have moved on.

Where is the current blog?

The current engineering blog, with the latest posts, is at /blog/.

Why keep archive posts online rather than deleting them?

Because the background material is usually still sound even when the recommendations have moved on, and the URLs are referenced elsewhere. Each archive post is labelled and links forward to current coverage where it exists.

How can I tell whether an archive post has been superseded?

Each carries a dated historical-archive banner and, where the field has moved, a forward note summarising what changed and linking to the current article.