lingo.lol is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for linguists, philologists, and other lovers of languages.

Server stats:

54
active users

#iam

0 posts0 participants0 posts today
LMG Security<p>Non-Human Identities: The Hidden Risk in Your Stack</p><p>Non-human identities (NHIs)—like API keys, service accounts, and OAuth tokens—now outnumber human accounts in many enterprises. But are you managing them securely? With 46% of organizations reporting compromises of NHI credentials just this year, it’s clear: these powerful, often-overlooked accounts are the next cybersecurity frontier.</p><p>Read The Hacker News article for more details: <a href="https://thehackernews.com/2025/06/the-hidden-threat-in-your-stack-why-non.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">thehackernews.com/2025/06/the-</span><span class="invisible">hidden-threat-in-your-stack-why-non.html</span></a></p><p><a href="https://infosec.exchange/tags/IdentitySecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdentitySecurity</span></a> <a href="https://infosec.exchange/tags/CyberRisk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberRisk</span></a> <a href="https://infosec.exchange/tags/APIsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>APIsecurity</span></a> <a href="https://infosec.exchange/tags/NHIs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NHIs</span></a> <a href="https://infosec.exchange/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://infosec.exchange/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://infosec.exchange/tags/CISO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CISO</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/MachineIdentities" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MachineIdentities</span></a> <a href="https://infosec.exchange/tags/ZeroTrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ZeroTrust</span></a> <a href="https://infosec.exchange/tags/RiskManagement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RiskManagement</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://infosec.exchange/tags/ITsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITsecurity</span></a></p>
FusionDirectory<p>C'est le deuxième jour des assises du <span class="h-card" translate="no"><a href="https://bird.makeup/users/csiesr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>csiesr</span></a></span> <span class="h-card" translate="no"><a href="https://techhub.social/@benoitmortier" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>benoitmortier</span></a></span> vous attend sur le stand pour vous montrer les dernières nouveautés de <span class="h-card" translate="no"><a href="https://pouet.chapril.org/@fusiondirectory" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fusiondirectory</span></a></span> . Vous présentez aussi nos services de <a href="https://pouet.chapril.org/tags/conseil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>conseil</span></a>, <a href="https://pouet.chapril.org/tags/accompagnement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>accompagnement</span></a>, <a href="https://pouet.chapril.org/tags/formations" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>formations</span></a> <a href="https://pouet.chapril.org/tags/logiciellibre" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>logiciellibre</span></a> <a href="https://pouet.chapril.org/tags/rest" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rest</span></a> <a href="https://pouet.chapril.org/tags/api" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>api</span></a> <a href="https://pouet.chapril.org/tags/workflow" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>workflow</span></a> <a href="https://pouet.chapril.org/tags/esr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>esr</span></a> <a href="https://pouet.chapril.org/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> <a href="https://pouet.chapril.org/tags/identites" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>identites</span></a> <a href="https://pouet.chapril.org/tags/gia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gia</span></a> <a href="https://pouet.chapril.org/tags/assisesducsiesr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>assisesducsiesr</span></a></p>
Benjamin<p>Is it like actually POSSIBLE to restrict user access to ANY client in Keycloak?<br>So far I find a lot of answers to this question, many of which are many years old, but none work.<br>No matter what policies I configure, I keep being able to log in to an application even though it feels like I shouldn't be.</p><p>Restriction access to clients should not be this hard.</p><p><a href="https://toot.berlin/tags/Keycloak" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Keycloak</span></a> <a href="https://toot.berlin/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a></p>
LemonLDAP::NG<p>🍋 LemonLDAP::NG 2.21 is out!</p><p>📃 This new release includes improvements on OpenID Connect and CAS protocols, Loki logger, public notifications and much more.</p><p>🔗 Read our release notes: <a href="https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">projects.ow2.org/view/lemonlda</span><span class="invisible">p-ng/lemonldap-ng-2-21-0-is-out/</span></a></p><p><span class="h-card" translate="no"><a href="https://fosstodon.org/@ow2" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ow2</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@worteks_com" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>worteks_com</span></a></span> </p><p><a href="https://fosstodon.org/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://fosstodon.org/tags/SSO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSO</span></a> <a href="https://fosstodon.org/tags/CAS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CAS</span></a> <a href="https://fosstodon.org/tags/SAML" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SAML</span></a> <a href="https://fosstodon.org/tags/OpenIDConnect" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenIDConnect</span></a> <a href="https://fosstodon.org/tags/OW2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OW2</span></a> <a href="https://fosstodon.org/tags/lemonldap" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>lemonldap</span></a> <a href="https://fosstodon.org/tags/lemonldapng" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>lemonldapng</span></a> <a href="https://fosstodon.org/tags/Passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Passkeys</span></a> <a href="https://fosstodon.org/tags/Passwordless" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Passwordless</span></a> <a href="https://fosstodon.org/tags/WebAuthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebAuthn</span></a> <a href="https://fosstodon.org/tags/FIDO2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FIDO2</span></a> <a href="https://fosstodon.org/tags/Loki" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Loki</span></a> <a href="https://fosstodon.org/tags/WebSSO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebSSO</span></a> <a href="https://fosstodon.org/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://fosstodon.org/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeSoftware</span></a> <a href="https://fosstodon.org/tags/LogicielLibre" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LogicielLibre</span></a> <a href="https://fosstodon.org/tags/Perl" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Perl</span></a></p>
LDAP Tool Box Project<p>🆕 LDAP Tool Box Service Desk 0.6.2 released!</p><p>ℹ️ LDAP Tool Box Service Desk is a web application for administrators and support teams. It allows to browse accounts in an LDAP directory, view and update their password and security status.</p><p>🔗 News on OW2 : <a href="https://projects.ow2.org/view/ldaptoolbox/ltb-service-desk-0-6-2-released/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">projects.ow2.org/view/ldaptool</span><span class="invisible">box/ltb-service-desk-0-6-2-released/</span></a><br>🔗 Release on GitHub : <a href="https://github.com/ltb-project/service-desk/releases/tag/v0.6.2" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/ltb-project/service</span><span class="invisible">-desk/releases/tag/v0.6.2</span></a><br>🔗 Download : <a href="https://ltb-project.org/download.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">ltb-project.org/download.html</span><span class="invisible"></span></a></p><p><a href="https://floss.social/tags/LDAP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LDAP</span></a> <a href="https://floss.social/tags/OpenLDAP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenLDAP</span></a> <a href="https://floss.social/tags/ActiveDirectory" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ActiveDirectory</span></a> <a href="https://floss.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://floss.social/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeSoftware</span></a> <a href="https://floss.social/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://floss.social/tags/IGA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IGA</span></a></p>
FusionDirectory<p>FusionDirectory vous présente sa toute nouvelle suite logicielle !</p><p>Vous l’attendiez depuis longtemps 😎 !</p><p>Mais, pourquoi parler de suite logicielle, me direz-vous ?</p><p>Nous sommes donc heureux de vous présenter FusionDirectory 1.5, FusionDirectory Orchestrator 1.1, FusionDirectory Integrator 1.2</p><p>Ces trois composants constituent dès à présent la suite logicielle FusionDirectory.</p><p>Cette nouvelle version est centrée majoritairement autour de notre moteur de workflow <a href="https://pouet.chapril.org/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> </p><p><a href="https://www.fusiondirectory.org/fusiondirectory-vous-presente-sa-toute-nouvelle-suite-logicielle/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">fusiondirectory.org/fusiondire</span><span class="invisible">ctory-vous-presente-sa-toute-nouvelle-suite-logicielle/</span></a></p>
נקודה ופסיק; Semicolon<p>I think therefore Identity &amp; Access Management.</p><p><a href="https://tooot.im/tags/aws" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aws</span></a> <a href="https://tooot.im/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> <a href="https://tooot.im/tags/IdentityAndAccessManagement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IdentityAndAccessManagement</span></a></p>
50+ Music<p>"After the Love Has Gone" is a song by <a href="https://mastodon.online/tags/EarthWindAndFire" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EarthWindAndFire</span></a>, released in 1979 as the second single from their ninth studio album <a href="https://mastodon.online/tags/IAm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAm</span></a> on <a href="https://mastodon.online/tags/ARC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ARC</span></a>/#ColumbiaRecords. The song reached No. 2 on both the US Billboard Hot 100 (behind <a href="https://mastodon.online/tags/theKnack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>theKnack</span></a>'s "<a href="https://mastodon.online/tags/MySharona" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MySharona</span></a>") and the Billboard <a href="https://mastodon.online/tags/HotRAndBSingles" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HotRAndBSingles</span></a> chart, No. 3 on the Billboard <a href="https://mastodon.online/tags/AdultContemporary" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AdultContemporary</span></a> chart, and No. 4 on the <a href="https://mastodon.online/tags/UKSinglesChart" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UKSinglesChart</span></a>. <a href="https://mastodon.online/tags/AfterTheLoveHasGone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AfterTheLoveHasGone</span></a> was certified gold in the US by the <a href="https://mastodon.online/tags/RIAA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RIAA</span></a> and silver in the UK by the <a href="https://mastodon.online/tags/BPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BPI</span></a>. <br><a href="https://www.youtube.com/watch?v=0TC0iH1MmzY" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=0TC0iH1MmzY</span><span class="invisible"></span></a></p>
Paul Sanders 😎<p>Fancy some typical <a href="https://infosec.exchange/tags/linkedin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linkedin</span></a> posts about <a href="https://infosec.exchange/tags/Yobah" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Yobah</span></a>? </p><p>It’ll be written to fit into the algorithm, but you might find some cool info or news. Most of my upcoming <a href="https://infosec.exchange/tags/blog" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>blog</span></a> posts on <a href="https://infosec.exchange/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a>, <a href="https://infosec.exchange/tags/zerotrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>zerotrust</span></a> and <a href="https://infosec.exchange/tags/entraID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>entraID</span></a> will be posted here first.</p><p>Would love it if you could drop us a follow :)</p><p><a href="https://www.linkedin.com/company/the-yobah-network/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">linkedin.com/company/the-yobah</span><span class="invisible">-network/</span></a></p>
Paul Sanders 😎<p>If you want to know more about <a href="https://infosec.exchange/tags/yobah" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yobah</span></a>, then why not visit the website at <a href="https://yobah.co.uk" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">yobah.co.uk</span><span class="invisible"></span></a>?</p><p> <a href="https://infosec.exchange/tags/introduction" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>introduction</span></a> <a href="https://infosec.exchange/tags/strategy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>strategy</span></a> <a href="https://infosec.exchange/tags/architect" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>architect</span></a> <a href="https://infosec.exchange/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> <a href="https://infosec.exchange/tags/zerotrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>zerotrust</span></a> <a href="https://infosec.exchange/tags/infrastructure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infrastructure</span></a> <a href="https://infosec.exchange/tags/sccm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sccm</span></a> <a href="https://infosec.exchange/tags/manchester" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>manchester</span></a> <a href="https://infosec.exchange/tags/uk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>uk</span></a> <a href="https://infosec.exchange/tags/Yobah" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Yobah</span></a> <a href="https://infosec.exchange/tags/consultancy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>consultancy</span></a></p>
Paul Sanders 😎<p>Think it’s time to update my <a href="https://infosec.exchange/tags/introduction" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>introduction</span></a> post. </p><p>Hi! </p><p>I’m a <a href="https://infosec.exchange/tags/strategy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>strategy</span></a> <a href="https://infosec.exchange/tags/architect" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>architect</span></a> by trade, focusing mostly on <a href="https://infosec.exchange/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> and <a href="https://infosec.exchange/tags/zerotrust" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>zerotrust</span></a> - albeit a long history in <a href="https://infosec.exchange/tags/infrastructure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infrastructure</span></a> architecture. Cut my teeth as it were during the virtualisation revolution (I feel older than that 😂) </p><p>Prior to that, I did desktop builds using Norton ghost and then <a href="https://infosec.exchange/tags/sccm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sccm</span></a>.</p><p>I live in <a href="https://infosec.exchange/tags/manchester" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>manchester</span></a>, <a href="https://infosec.exchange/tags/uk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>uk</span></a> and started <a href="https://infosec.exchange/tags/Yobah" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Yobah</span></a> - a boutique <a href="https://infosec.exchange/tags/consultancy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>consultancy</span></a> working on strategy transformation.</p><p>Feel free to reach out and say hi!</p>
Jinnare-introduction, long
50+ Music<p>"After the Love Has Gone" is a song by <a href="https://mastodon.online/tags/EarthWindAndFire" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EarthWindAndFire</span></a>, released in 1979 as the second single from their ninth studio album <a href="https://mastodon.online/tags/IAm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAm</span></a> on <a href="https://mastodon.online/tags/ARC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ARC</span></a>/#ColumbiaRecords. The song reached No. 2 on both the US Billboard Hot 100 (behind <a href="https://mastodon.online/tags/theKnack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>theKnack</span></a>'s "<a href="https://mastodon.online/tags/MySharona" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MySharona</span></a>") and the Billboard <a href="https://mastodon.online/tags/HotRAndBSingles" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HotRAndBSingles</span></a> chart, No. 3 on the Billboard <a href="https://mastodon.online/tags/AdultContemporary" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AdultContemporary</span></a> chart, and No. 4 on the <a href="https://mastodon.online/tags/UKSinglesChart" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UKSinglesChart</span></a>. <a href="https://mastodon.online/tags/AfterTheLoveHasGone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AfterTheLoveHasGone</span></a> was certified gold in the US by the <a href="https://mastodon.online/tags/RIAA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RIAA</span></a> and silver in the UK by the <a href="https://mastodon.online/tags/BPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BPI</span></a>. <br><a href="https://www.youtube.com/watch?v=7tuJfud4W6U" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/watch?v=7tuJfud4W6</span><span class="invisible">U</span></a></p>
FusionDirectory<p>Les <span class="h-card" translate="no"><a href="https://mastodon.gougere.fr/@LesJRES" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LesJRES</span></a></span> journées réseaux de l’enseignement et de la recherche se déroulent à Rennes cette année du 10 au 13 décembre 2024.</p><p>FusionDirectory y sera présent comme à chaque fois 😎. Nous venons cette année avec notre hôte remplie de nouveautés 😉</p><p><a href="https://www.fusiondirectory.org/venez-faire-le-plein-de-nouveautes-au-jres-2024-a-rennes-avec-fusiondirectory/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">fusiondirectory.org/venez-fair</span><span class="invisible">e-le-plein-de-nouveautes-au-jres-2024-a-rennes-avec-fusiondirectory/</span></a></p><p>Nous sommes impatients de vous rencontrer 😎 et de partager toutes ces nouveautés avec vous</p><p><a href="https://pouet.chapril.org/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> <a href="https://pouet.chapril.org/tags/rest" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rest</span></a> <a href="https://pouet.chapril.org/tags/api" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>api</span></a> <a href="https://pouet.chapril.org/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://pouet.chapril.org/tags/workflow" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>workflow</span></a> <a href="https://pouet.chapril.org/tags/supann" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>supann</span></a> <a href="https://pouet.chapril.org/tags/cycledevie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cycledevie</span></a> <a href="https://pouet.chapril.org/tags/notifications" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>notifications</span></a> <a href="https://pouet.chapril.org/tags/audit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>audit</span></a> <a href="https://pouet.chapril.org/tags/orchestrator" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>orchestrator</span></a> <span class="h-card" translate="no"><a href="https://bird.makeup/users/csiesr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>csiesr</span></a></span> <span class="h-card" translate="no"><a href="https://mstdn.social/@renater" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>renater</span></a></span> <span class="h-card" translate="no"><a href="https://mamot.fr/@plossra_a" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>plossra_a</span></a></span> <span class="h-card" translate="no"><a href="https://birdsite.wilde.cloud/users/cnll_fr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cnll_fr</span></a></span></p>
WHY☎️5555<p>I've written a new blog post taking a moderately deep dive into "Threat Modeling YubiKeys and Passkeys"</p><p><a href="https://yawnbox.is/blog/threat-modeling-yubikeys-and-passkeys/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">yawnbox.is/blog/threat-modelin</span><span class="invisible">g-yubikeys-and-passkeys/</span></a></p><p>I greatly welcome feedback as I want to make sure I'm not misrepresenting anything. I want to make it better if it can be improved. I'm happy to be wrong, just please provide details and links!</p><p>also, i need a job! if you like my work, maybe you know of something where i'd be a good fit.</p><p><a href="https://disobey.net/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://disobey.net/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://disobey.net/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://disobey.net/tags/FIDO2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FIDO2</span></a> <a href="https://disobey.net/tags/WebAuthn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WebAuthn</span></a> <a href="https://disobey.net/tags/YubiKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>YubiKey</span></a> <a href="https://disobey.net/tags/YubiKeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>YubiKeys</span></a> <a href="https://disobey.net/tags/passkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkey</span></a> <a href="https://disobey.net/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a> <a href="https://disobey.net/tags/GetFediHired" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GetFediHired</span></a></p>
HN Security<p>Our security researchers @cod_rse@twitter.com and <span class="h-card" translate="no"><a href="https://infosec.exchange/@inode" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>inode</span></a></span> conducted a security assessment on <a href="https://infosec.exchange/tags/Keycloak" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Keycloak</span></a>, identifying significant vulnerabilities impacting this open-source <a href="https://infosec.exchange/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> solution.</p><p>Read the full article at <a href="https://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.humanativaspa.it/an-a</span><span class="invisible">nalysis-of-the-keycloak-authentication-system</span></a></p>
GÉANT<p>The <a href="https://mstdn.social/tags/TNC25" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TNC25</span></a> Call for Proposals for single presentations and side meetings is now open!</p><p>Whether you’re a long-standing member of the community, or have just joined the <a href="https://mstdn.social/tags/research" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>research</span></a> and <a href="https://mstdn.social/tags/education" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>education</span></a> world and are working on a cool project, TNC25 invites you to submit your proposals!</p><p>➡️ Check guidelines &amp; apply before 28 Nov: <a href="https://tnc25.geant.org/submit" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">tnc25.geant.org/submit</span><span class="invisible"></span></a></p><p><a href="https://mstdn.social/tags/NRENs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NRENs</span></a> <a href="https://mstdn.social/tags/HigherEducation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HigherEducation</span></a> <a href="https://mstdn.social/tags/HigherEd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HigherEd</span></a> <a href="https://mstdn.social/tags/Networking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Networking</span></a> <a href="https://mstdn.social/tags/Network" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Network</span></a> <a href="https://mstdn.social/tags/connectivity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>connectivity</span></a> <a href="https://mstdn.social/tags/cloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cloud</span></a> <a href="https://mstdn.social/tags/TrustAndIdentity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TrustAndIdentity</span></a> <a href="https://mstdn.social/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://mstdn.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mstdn.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mstdn.social/tags/OpenScience" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenScience</span></a> <a href="https://mstdn.social/tags/HPC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HPC</span></a> <a href="https://mstdn.social/tags/Quantum" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Quantum</span></a> <a href="https://mstdn.social/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a></p>
WHY☎️5555<p><a href="https://disobey.net/tags/WindowsHello" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsHello</span></a> will soon offer users an option to sync their passkeys to their Microsoft account making them no longer device-bound</p><p>again, this changes the threat model for enterprises, if they care about such details. a device-bound passkey means the private key material exists no where else in the world. Cloud syncing of private keys is basically the same for TOTP private seeds -- those cloud providers, while encrypting the data at rest, do in fact have clear-text access to those secrets -- making them targets of social engineers, law enforcement, nation states and other hackers.</p><p>(only an end-to-end encryption cloud storage solution like Apple's Advanced Data Protection would protect synced passkeys)</p><p>HT <span class="h-card" translate="no"><a href="https://social.tchncs.de/@jesterchen" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jesterchen</span></a></span> </p><p><a href="https://blogs.windows.com/windowsdeveloper/2024/10/08/passkeys-on-windows-authenticate-seamlessly-with-passkey-providers/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blogs.windows.com/windowsdevel</span><span class="invisible">oper/2024/10/08/passkeys-on-windows-authenticate-seamlessly-with-passkey-providers/</span></a></p><p><a href="https://disobey.net/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://disobey.net/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://disobey.net/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a></p>
LeeRayl<p>In my 18 years of IAM work the biggest mistake I see is rushing to secure 1 thing not all the things.</p><p>“We need SAML for AWS for &lt;insert governance here&gt;”</p><p>That is the wrong way to start any new or rebuilding of a IAM program or project.</p><p>The complexity of IAM is worth the time to plan. </p><p>Example: defining the source of truth, ensuring the integrity and confidentiality is critical, roles and entitlements are needed, an IdP needs to be established and tested, source of truth matches the directory, syncing the directory and IdP, implementation of authentication of the users with the IdP and MFA/ZTA configured.</p><p>All that is really important and barely enough to illustrate my point of the amount of work for that one app requires Picasso like experience with a Michelangelo touch </p><p><a href="https://infosec.exchange/tags/IAM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IAM</span></a> <a href="https://infosec.exchange/tags/SSO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSO</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a></p>
smeg<p>I think digitally stored passkeys completely miss the point of multi-factor authentication. It's a cheat and we should be discouraging this capability. It's not real mfa compliance.</p><p><a href="https://assortedflotsam.com/tags/iam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iam</span></a> <a href="https://assortedflotsam.com/tags/mfa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mfa</span></a> <a href="https://assortedflotsam.com/tags/grc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>grc</span></a> <a href="https://assortedflotsam.com/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a></p>