Usually we tend to center the concept of Authentication to mere users, through and exhibited password as a credential But beyond the user, how to be sure about authenticity of other assets ? For example, how can we be sure about, once the user is authenticated,