YoVDO

From Keyless to Careless - Abusing Misconfigured OIDC Authentication in Cloud Environments

Offered By: BSidesLV via YouTube

Tags

Cloud Security Courses JSON Web Tokens Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the security risks associated with misconfigured OpenID Connect (OIDC) authentication in cloud environments in this 17-minute conference talk from BSidesLV. Delve into the concept of "keyless authentication" supported by major cloud providers like AWS, Azure, and Google Cloud, and understand its popularity in CI/CD pipelines. Discover how easily misconfigured AWS IAM roles using keyless authentication can be exploited by unauthenticated attackers to retrieve cloud credentials and compromise entire environments. Learn from real-world examples, including a case study involving the UK government's AWS account. Gain insights on identifying vulnerable roles in your own environment and implementing higher-level guardrails to prevent human errors from escalating into data breaches. Presented by Christophe Tafani-Dereeper, this talk offers valuable knowledge for cloud security professionals and developers working with OIDC authentication.

Syllabus

Breaking Ground, Wed, Aug 7, 20:00 - Wed, Aug 7, CDT


Taught by

BSidesLV

Related Courses

Architecting Microsoft Azure Solutions
Microsoft via edX
Internetwork Security
Indian Institute of Technology, Kharagpur via Swayam
Network Security
Georgia Institute of Technology via Udacity
Microsoft Professional Orientation : Cloud Administration
Microsoft via edX
Cyber Threats and Attack Vectors
University of Colorado System via Coursera