In the journey through information security, you will frequently encounter OAuth 2.0. While OAuth is excellent at authorization, it was never actually designed for authentication. To solve this, OIDC, or OpenID Connect, was created. Think of it this way: OAuth 2.0 is the key to a hotel room, while OIDC is the ID card that proves you are the person who booked it.
A place to share links and articles that i have found helpful. This blog tends to be more offensive security minded. Basically it is a collection of notes that I will update periodically. None of this is set in stone, and I could very well be wrong on most of it. Just saying.
Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts
identity rambles....
So if
the y-axis is access to a system, and the x-axis is access across a network.
The Y access then becomes also access to data on the system, and the x-axis becomes access across the network to data.
If you can quantify the data, then you can assign numbers to number of systems, and then a separate set of numbers to levels of access to each system, Maybe?
How is the user able to prove that their authorized to access the system and the data it contains.
Okay, zero trust, but how do you do a new user?
How do you establish trust?
Subscribe to:
Posts (Atom)