3 ms·
I’m surprised a feature like this didn’t require a detailed threat model with explanation of mitigations before launch. Don’t think this “authentication” method
by dc-programmer 5y ago
I’m surprised a feature like this didn’t require a detailed threat model with explanation of mitigations before launch. Don’t think this “authentication” method would’ve past muster
- staticassertion 5y agoMe too. We have a multi-tenant system and we did threat modeling, immediately calling out that while we had network restrictions that we should assume those will fail and we'll add mTLS and an out of band token. That took almost no time or effort to realize.