4 ms·
I agree about the messaging, but in terms of actual security: What about your service provider’s “Bob”?
by codeflo 3y ago
I agree about the messaging, but in terms of actual security: What about your service provider’s “Bob”?
- easton 3y agoIf Azure AD was compromised your clients were all probably compromised too, so in that way you’re probably fine. I’m sure that Microsoft/Okta/Google hold the keys in some kind of HSM or whatever, but there’s probably a Bob there that could get in if he really wanted to. You have to figure out what you’re threat modeling for, most people aren’t worried about the big SSO providers being breached because it would be expensive to work around them completely.
- imglorp 3y agoBut AD is compromised and Azure clients are open... https://news.ycombinator.com/item?id=36770235 https://news.ycombinator.com/item?id=36770235
- ilyt 3y agoAnd you can just wash hands because you used "industry's best practice" and continue the security theatre.
- strogonoff 3y agoChoosing a supplier is not washing hands of the issue, if you are a serious business. If you are found to not have done due diligence and have chosen a known vulnerable supplier, you would be seen as equally or more liable compared to having yourself implemented a solution that was found vulnerable. In fact, I imagine your customers can sue you in the former instance and likely win more easily than in the latter (IANAL).
- nostoc 3y agoIt's "Bob" all the way down
- crest 3y agoDon't worry they have a provider too. Oh and that provider is your customer and they store their secret in your secret manager, but you didn't know that until after the post mortem. /s
- selfmodruntime 3y agoThen it's mostly a matter of insurance, so problem solved I guess