Tag: credential management

  • Simon Willison’s Weblog: Grant Negotiation and Authorization Protocol (GNAP)

    Source URL: https://simonwillison.net/2024/Oct/14/grant-negotiation-and-authorization-protocol-gnap/#atom-everything Source: Simon Willison’s Weblog Title: Grant Negotiation and Authorization Protocol (GNAP) Feedly Summary: Grant Negotiation and Authorization Protocol (GNAP) RFC 9635 was published a few days ago. GNAP is effectively OAuth 3 – it’s a newly standardized design for a protocol for delegating authorization so an application can access data on your…

  • Hacker News: Passkey Privacy Issues

    Source URL: https://lapcatsoftware.com/articles/2024/8/8.html Source: Hacker News Title: Passkey Privacy Issues Feedly Summary: Comments AI Summary and Description: Yes Summary: The text highlights significant privacy issues associated with Apple’s passkey implementation, particularly regarding the automatic generation of passkeys upon the use of iCloud Keychain. The author expresses concerns about the extensive personal information Apple collects and…

  • CSA: Identity Security Best Practices for SaaS Apps

    Source URL: https://www.cyberark.com/resources/blog/building-secure-and-compliant-saas-apps-identity-security-best-practices Source: CSA Title: Identity Security Best Practices for SaaS Apps Feedly Summary: AI Summary and Description: Yes Summary: The text provides a comprehensive overview of identity security best practices essential for securing access to cloud services, particularly in relation to compliance with frameworks like SOC II and NIST. It emphasizes concepts such…

  • Cloud Blog: "WireServing" Up Credentials: Escalating Privileges in Azure Kubernetes Services

    Source URL: https://cloud.google.com/blog/topics/threat-intelligence/escalating-privileges-azure-kubernetes-services/ Source: Cloud Blog Title: "WireServing" Up Credentials: Escalating Privileges in Azure Kubernetes Services Feedly Summary: Written by: Nick McClendon, Daniel McNamara, Jacob Paullus   Executive Summary Mandiant disclosed this vulnerability to Microsoft via the Microsoft Security Response Center (MSRC) vulnerability disclosure program, and Microsoft has fixed the underlying issue. An attacker with…