Hi everyone! Tomorrow I m launching Sovereign AI Overseer, but I wanted to start a discussion today about a massive vulnerability we all just accept as "normal": Passwords.
If you run an agency or manage client sites, you know that "forgot password" tickets and brute-force botnets eat up your profit margins and server resources. Rate-limiting is just a band-aid.
I decided to deprecate the password field completely.
In my new architecture, I replaced it with native WebAuthn (Face ID / Touch ID). For active threats, I deployed a serverless Google Gemini 1.5 Pro AI Sentinel via a BYOI (Bring Your Own Infrastructure) model on Cloud Run to autonomously ban IPs in real-time.