YoVDO

Bridging Security Infrastructure Between the Data Center and AWS Lambda

Offered By: Black Hat via YouTube

Tags

Black Hat Courses AWS Lambda Courses

Course Description

Overview

Explore a comprehensive conference talk on bridging security infrastructure between data centers and AWS Lambda. Delve into Square's journey of migrating to the cloud while maintaining secure communication between microservices. Learn about workload identity architecture in AWS Lambda, identity sharing between data centers and cloud environments, and the challenges of integrating serverless technology with existing infrastructure. Discover various options for identity issuance, architectural decisions, and system components. Gain insights into application secrets management, security boundaries, and risk mitigation strategies. Understand the onboarding process and key considerations for implementing a secure serverless infrastructure that seamlessly integrates with traditional data center services.

Syllabus

Intro
Overview
How does it work?
The problem with serverless
System Goals
Square data center
Workload identity at Square
Shape of identity for Lambda
Identity issuance: what options were available?
Identity issuance decision
Architecture for identity issuance
Architecture Decision
System components
Hellol Lambda calling
Application Secrets: Keywhiz
Full decentralization?
Application secrets decision
Security Boundaries
Secrets Availability
How to onboard
Risk Mitigation Access all secrets
Summary


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube