Four identity providers hit by critical vulnerabilities in three days. The common root: systems that accept credentials without verifying the binding between key and identity. The cryptographic ...