Browse the blog by tag.
Tags are broad topic clusters that cut across the engineering blog — a fast way to pull together every post that touches FIDO, transit ticketing, or the Cyber Resilience Act. Click any tag for its post list.
How this page is organised
Every post on the AmbiSecure engineering blog is filed two ways, and the two are meant for different jobs:
- Categories (/blog/categories/) are the primary structure — one subject area per post, arranged the way the blog itself is organised. Start there if you want to read a topic in order.
- Tags (this page) are cross-cutting labels — a post can carry several. Start here if you want everything touching one technology or regulation regardless of which subject area it was filed under.
The cards below are sorted by post count, so the densest clusters appear first. A tag with two posts is a genuinely narrow topic, not an incomplete one. Tag pages are a navigation aid rather than destination pages, so they are excluded from search-engine indexes — the posts themselves, and the category pages, are the canonical entry points.
If you would rather search than browse, the blog search covers post titles, deks, and body text across both the modern blog and the engineering archive. To read in date order instead, start at page 1 and continue to page 2.
How are tags assigned?
Tags are applied by hand when a post is written, not generated from the text. A post gets a tag when it has something substantive to say about that subject — not merely because the term appears somewhere in the body. That is deliberate: an automatically extracted tag list would be larger and considerably less useful, because every passing mention of FIDO or PKI would pull a post into a cluster it does not really belong to.
The practical consequence is that tag pages here are smaller than you might expect and more accurate than you might expect. A tag carrying three posts means we have written three articles that genuinely address it. It does not mean the subject is marginal, and it does not mean the list is incomplete.
Two clusters overlap on purpose. Cyber Resilience Act and CRA both exist because the regulation is referred to both ways in practice, and readers arrive searching for each. Where two tags cover the same ground, the posts beneath them are largely the same set.
Tags are also stable. Once a post is tagged it keeps that tag, so a link to a tag page continues to mean what it meant when it was shared. When a subject grows enough to deserve its own reading order, it becomes a category rather than staying a tag.
All tags
MFA
8 posts
Cyber Security
8 posts
FIDO
7 posts
Transit
7 posts
Secure Element
6 posts
Smart Cards
5 posts
Passwordless
4 posts
Government Identity
3 posts
Cyber Resilience Act
4 posts
CRA
4 posts
Device Identity
4 posts
Enterprise
3 posts
Embedded Security
3 posts
AAGUID
2 posts
Attestation
2 posts
Recovery
2 posts
Hardware
2 posts
DESFire
2 posts
SAM
2 posts
JavaCard
2 posts
WebAuthn
2 posts
ePassport
2 posts
Biometrics
2 posts
AmbiSEC
2 posts
IoT Security
2 posts
Secure by Design
2 posts
PKI
1 post
Passkeys
1 post
Privacy
1 post