Evan Gilman

462 posts

Evan Gilman

Evan Gilman

@evan2645

Co-founder @spirl_inc, and @SPIFFEio + SPIRE maintainer. Co-author of Zero Trust Networks. ex-@pagerduty ex-@scytale_io ex-@VMware

San Francisco, CA Beigetreten Ağustos 2012
102 Folgt844 Follower
Evan Gilman retweetet
Defakto
Defakto@DefaktoSecurity·
The potential of AI agents should not make us forget that we already have the tools needed to secure them. Just follow the advice of an 11th-century monk, and "start by doing what's necessary." Read more in @PieterKasselman's blog hubs.li/Q037pyqT0 #AI #AISecurity #identity
English
0
1
2
281
Evan Gilman retweetet
Tal Be'ery
Tal Be'ery@TalBeerySec·
Pass-the-{token} attacks are still very much relevant. Tokens may change: Cookie, NT Hash, Kerberos ticket, MFA token, ... However, the problem is not in the "token" but in the "pass". We need a solutions to make tokens stay put, such as device and channel binding.
Microsoft Threat Intelligence@MsftSecIntel

Microsoft has detected a 111% year-over-year increase in token replay attacks, and incidents are continuing to grow. msft.it/6011lSgZ7

English
5
41
151
21.6K
Evan Gilman retweetet
Ryan Hurst
Ryan Hurst@rmhrisk·
Put some thoughts together on how to think about ACME and SPIFFE. The TL;DR is: ACME is about proving control of an identifier, while SPIFFE is about assigning and managing identifiers dynamically to enable the authorization of the subjects of those identifiers. unmitigatedrisk.com/?p=820
English
0
4
9
808
Evan Gilman retweetet
SPIFFE
SPIFFE@SPIFFEio·
In case you missed the SPIFFE Virtual meetup last month, here are the recordings. Thank you to presenters from Coinbase, Indeed, and HPE for sharing their insights and experiences youtube.com/playlist?list=… #SPIFFE #ZeroTrust
English
0
7
11
1.2K
Evan Gilman retweetet
Volkan Özçelik 🦌
Volkan Özçelik 🦌@vadidekivolkan·
Psst… In case you want to hear me ranting for two hours about secrets, SPIFFE, SPIRE, Turtles, passport, piano, kids, teenagers, and Neurology this is the video recording of today’s Enlightning » youtube.com/watch?v=EB6AJT…
YouTube video
YouTube
English
0
2
4
685
Evan Gilman retweetet
François Michel
François Michel@furanzu_·
SSH3 with ACME just naturally solves the classical Trust On First Use problem of SSH for VMs with hostnames such as @Azure VMs. Easily implemented in SSH3 v0.1.6 using @caddyserver's certmagic.✨ Native access to the HTTPS ecosystem in SSH is a real game changer, here's why:
François Michel tweet mediaFrançois Michel tweet media
English
2
15
46
8.7K
Evan Gilman retweetet
Defakto
Defakto@DefaktoSecurity·
Are you working with SPIFFE and wondering what should go into your SPIFFE ID? Check out our post where we teach you what to consider for your IDs. buff.ly/41RUrIu
English
0
2
4
214
Evan Gilman retweetet
Duffie Cooley
Duffie Cooley@mauilion·
These two are such a fun couple of humans both of them lift others up and share that incredible knowledge they’ve learned everyday! With @evan2645 and @sublimino
Duffie Cooley tweet media
English
1
3
25
1.6K
Evan Gilman retweetet
Ryan Hurst
Ryan Hurst@rmhrisk·
In operating system design, the user context in which tasks operate is factored into the design to ensure the desired security properties. In application design, this consideration is often overlooked, with applications usually running as monolithic structures that are blindly trusted to function correctly. The cloud typically employs a microservice-based design, which is similar to approaches used in operating systems. This is great, but unlike operating systems, these components are distributed. This is a important distinction because these micro-services largely still rely on blind trust that these components function as intended. While this blind trust is present in operating systems, it's more tolerable there since it all runs on a single host under a consistent security architecture. In cloud systems, that's seldom the case, exposing systems to attacks and amplifying the blast radius of a compromise when it happens. This misplaced trust in components is often the reason for the frequent tenant boundary violations seen in multi-tenant systems. By adopting cryptographic access controls and cryptographically verifiable auditing in these systems, inspired by how Signal incorporated cryptography and verifiability into messaging, we can move away from this blind trust. This reduces the impact of breaches, enhancing the ability to respond effectively and promptly during security incidents.
English
0
2
6
718
Evan Gilman retweetet
Eli Nesterov
Eli Nesterov@elinesterov·
SPIFFE Community Day kick-off!
Eli Nesterov tweet media
English
0
1
10
572
Evan Gilman retweetet
Ryan Hurst
Ryan Hurst@rmhrisk·
Here are a few key management lessons from decades of successes and failures.
Ryan Hurst tweet media
English
2
3
8
2K
Evan Gilman
Evan Gilman@evan2645·
We have some amazing speakers lined up for SPIFFE Community Day next Friday 🙌🙌🙌 you should definitely attend if you're able to! Hybrid event, but in-person attendees in SF will have an unconference bit at the end 😀 see you there! …ecommunityday-fall2023.splashthat.com
English
0
3
11
1.1K