A practical guide to setting up keyless access to Azure Cosmos DB using managed identities and data plane RBAC. Covers the three key questions for access control: who (managed identity), what (built-in data roles), and where (scope). Explains the critical distinction between control plane and data plane RBAC, walks through assigning the built-in Data Contributor role via Azure CLI, and shows how to use DefaultAzureCredential in the .NET SDK to authenticate without connection strings or secrets.
Nguồn: https://devblogs.microsoft.com/cosmosdb/which-azure-cosmos-db-role-does-my-app-need. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
Vercel Flags giờ đây tự động xác thực thông qua OIDC tokens ngắn hạn mà không cần SDK Keys hay biến môi trường FLAGS cho các triển khai trên Vercel. Chỉ cần vercel link và vercel env pull là đủ cho phát triển local, trong khi các dự án cũ vẫn giữ nguyên yêu cầu SDK Keys cho các trường hợp đặc biệt.
Lập trình viên cần đọc bài này để hiểu cách tối ưu hóa quản lý tính năng động (flags) trong dự án Vercel mới nhất, giảm thiểu rủi ro về bảo mật khi sử dụng SDK Keys và khám phá giải pháp tự động hóa cho phát triển và triển khai.
A security executive exempted themselves from MFA requirements they enforced on other employees, illustrating a classic 'one rule for workers, another for executives' double standard in corporate security policy. The story highlights how security leadership can undermine the very practices they mandate for others.
AI agent deployments frequently stall at security review due to undefined identity models and overly broad permissions. Four key identity decisions must be made for every agentic system: using workload identity over shared service accounts, preferring short-lived credentials over static API keys, implementing brokered session access instead of direct credential handoff, and capturing full identity lineage rather than fragmented logs. Shared accounts and long-lived keys create compounding blast radius risks — Nightfall AI data shows 350 secrets exposed per 100 employees annually, with 35% still active. The recommended approach is to standardize identity at the platform layer using centralized identity providers, policy engines, and credential brokers, rather than rebuilding auth for each agent.
A walkthrough for setting up an apex domain redirect to the www subdomain in Azure Static Web Apps. Covers DNS configuration using CNAME for www and A record for the apex domain, TXT-based domain validation, and using the default domain setting in Azure Portal to trigger the redirect from apex to www automatically.
South Africa's mobile operators, coordinated through the Association of Comms & Technology (ACT), have agreed a framework to strengthen SIM card registration and combat SIM fraud. The framework introduces enhanced identity verification, tighter registration controls, improved compliance monitoring, and closer cooperation with law enforcement. It serves as an interim industry-led measure while ACT simultaneously pushes for legislative reform of Rica's section 40, which governs SIM registration. Key issues addressed include the bulk pre-registration of SIMs by distributors ('pre-Rica'd' cards) and packaging that exposes SIM identifying numbers. Proposed solutions include biometric authentication at registration points and secure SIM packaging. The Competition Commission was consulted to ensure the inter-operator coordination does not raise competition concerns.
Identity verification (IdV) has become conflated with document authentication, creating dangerous confusion about what level of assurance is actually being achieved. Document authentication, selfie matching, and liveness detection each answer different questions and are not equivalent to full identity proofing or contextual identity verification. Identity proofing establishes that an identity exists and belongs to a person; identity verification determines whether that identity should be trusted for a specific interaction. Point-in-time checks are insufficient because identity trust changes over time. Organizations should evaluate IdV solutions by the assurance level they provide relative to transaction risk, not by feature checklists. The post also covers NIST IALs, KYC vs. IdV distinctions, synthetic identity fraud, and the limitations of biometric matching against deepfakes.
Unverified applications pose a significant but often overlooked credential theft risk for businesses. Attackers exploit fake authentication requests, embedded malware, excessive permissions, and session/token hijacking through apps that appear legitimate. Key prevention strategies include establishing formal application approval processes, implementing MFA and role-based access controls, adopting a Zero Trust model, restricting third-party app permissions, monitoring authentication activity continuously, and educating employees about shadow IT risks. An incident response plan covering rapid credential revocation, access investigation, and post-incident improvement rounds out a comprehensive defense posture.
Một chuyên viên mới tại Okta, hiện đảm nhiệm vai trò AI Builder Advocate, chia sẻ hành trình chuyển từ lập trình viên backend sang developer relations. Cô có nền tảng kỹ thuật vững chắc với Java, Spring Boot, Quarkus, Kubernetes và Docker, đồng thời tích cực tham gia cộng đồng với tư cách MongoDB Champion, đặc biệt hứng thú với lĩnh vực identity, security và AI tại Okta.
Những người có kinh nghiệm kỹ thuật như backend nhưng muốn chuyển hướng sang cộng đồng hoặc công tác phát triển cộng đồng nên tìm hiểu cách kết nối kiến thức kỹ thuật với chiến lược cộng đồng hiệu quả để mở rộng ảnh hưởng và đóng góp giá trị thực tế cho cộng đồng phát triển.