#authorization

|7eter l-|. l3oling 🧰galtzo@ruby.social
2025-05-17

My thoughts on how to make upgrading scary low level packages less scary

reddit.com/r/ruby/comments/1ko

#Ruby #Security #Authorization

|7eter l-|. l3oling 🧰galtzo@ruby.social
2025-05-17

🛠️ It is with a mix of temerity and trepidation that I announce oauth2 v2.0.10.

Biggest new feature: IETF RFC 7009 Token Revocation.

Many bugs fixed.

Test suite & matrix: 100% line & branch, every key minor version of every runtime dep, on every minor Ruby Engine, on every Platform.

#ruby #security #authorization

Please upgrade with confidence!

github.com/oauth-xx/oauth2

2025-05-15

[Перевод] Архитектурные принципы Spring Security. Часть первая

Команда Spring АйО перевела и адаптировала доклад Даниэля Гарнье-Муару “Spring Security Architecture Principles”, в котором на наглядных примерах рассказывается, как пользоваться возможностями Spring Security, не запутываясь на каждом шагу и не зарабатывая себе головную боль. Доклад будет опубликован тремя частями. В первой части будет рассказано об основных подходах к созданию цепочек фильтров, а также разработан простейший фильтр с красивым названием “Es prohibido” (“Это запрещено” в переводе с испанского).

habr.com/ru/companies/spring_a

#spring_security #java #kotlin #filterchain #filter #csrf #authorization #authentication

Who Let The Dogs Out 🐾ashed@mastodon.ml
2025-05-15

#android #opensource #foss #authentication #authorization #sso #iam

GitHub - casbin/awesome-auth: 📊 Software and Libraries for Authentication & Authorization & SSO & IAM

github.com/casbin/awesome-auth

2025-05-05

[Перевод] OpenAM и Zero Trust: Подтверждение критичных операций

Один из принципов нулевого доверия гласит: никогда не доверяй, всегда проверяй (Never trust, always verify). В этой статье мы рассмотрим, как реализовать соблюдение такого принципа в системе аутентификации на примере продуктов с открытым исходным кодом OpenAM и OpenIG .

habr.com/ru/articles/905824/

#openam #zero_trust #openig #authentication #authorization #mfa #otp #totp

2025-04-18

Hackers can craft a request, send it to the Asus router, and execute functions without authorization.

#hack #cybersecurity #Asus #authorization

cnews.link/asus-routers-affect

Hacker Newsh4ckernews
2025-04-13
Alvin Ashcraft 🐿️alvinashcraft@hachyderm.io
2025-04-08
Rod2ik 🇪🇺 🇨🇵 🇪🇸 🇺🇦 🇨🇦 🇩🇰 🇬🇱rod2ik
2025-04-02
Rod2ik 🇪🇺 🇨🇵 🇪🇸 🇺🇦 🇨🇦 🇩🇰 🇬🇱rod2ik.bsky.social@bsky.brid.gy
2025-04-02
Nebraska.CodeNebraskaCode
2025-03-26

Zhehui (Joe) Zhou, Pranjit Biswas, and Matt Ruwe have Sessions on Cloud Computing in July at Nebraska.Code().

nebraskacode.amegala.com

2025-03-25

Rust just got better access control! Gatehouse brings RBAC, ABAC, and ReBAC in one type-safe package 🦀

#rust #security #authorization github.com/thepartly/gatehouse

Hacker Newsh4ckernews
2025-03-24

Gatehouse – a composable, async-friendly authorization policy framework in Rust

github.com/thepartly/gatehouse

2025-03-10

Is anyone out there familiar enough with the Google Zanzibar-inspired authorization space to help me figure out how OpenFGA, SpiceDB, and Permify compare with one another? They all seem quite similar, and I’m struggling to rank them objectively. #authorization #zanzibar #openfga #permify #spicedb

2025-03-10

👋 Very stoked to announce that I will be speaking at #OWASP #Snowfroc this Friday at 11:00 in the Great Hall. The talk is entitled "Patterns of failure in modern #authorization" and it's mostly about why #authz is getting harder (instead of easier). I'll be citing some academic research but also looking at some interesting examples of authz failure at some fairly large, well-known brands. Hope to see you there! 🎤

p.s. I've never been to #Denver so looking forward to checking the city out a bit too. If you have suggestions for things to do (read: eat), let me know! 😄

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-04

@GossiTheDog the sheer fact that #MSPs & #CSPs can access clients' setups without proper #authorization [including #KYC / #KYB, #AuthCode|s and proper authorization via contract] is already sickening.

Such fundamental #ITsec fuckups are reasons alone not to use #Azure or any #Microsoft products & services at all...

  • I mean, it doesn't require #Mitnick-level skills to pull this off, since it doesn't necessitate #Lapsus-Style #SIMswap or other means to gain access...
2025-03-03

Identity must not stop at Authentication. There are two other As in AAA after all.

Join the Nearshore Cyber Online Community for FREE with this link: nearshorecyber.community/c/nea

2025-03-03

Identity must not stop at Authentication. There are two other As in AAA after all.

Join the Nearshore Cyber Online Community for FREE with this link: nearshorecyber.community/c/nea

#Identity #IAM #Authorization #Audit

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst