Home / Companies / Authentik Security / Blog / November 2023

November 2023 Summaries

5 posts from Authentik Security

Filter
Month: Year:
Post Summaries Back to Blog
The use of automation in cybersecurity has become increasingly popular, but it is not a replacement for human expertise and a proactive security mindset. While automated tools can excel in repetitive and routine tasks such as vulnerability scanning, they are limited in their ability to detect new threats, understand complex vulnerabilities, and respond to emerging threats. Human experts are still needed to configure and employ automated systems, adjust their performance in response to changing environments, and make informed decisions about security and organizational implications. Moreover, automation can actually exacerbate problems such as alert fatigue, data overload, and devaluing human expertise if overrelied upon. Instead, a healthy balance between automation and human expertise is necessary for effective cybersecurity.
Nov 30, 2023 2,191 words in the original blog post.
The author of this text is building a security stack for their open-source identity provider, Authentik Security, using free and open-source tools such as Loki, Wazuh, and CodeQL. They estimate that using these non-commercial security tools saves them approximately $100,000 annually. The security stack includes Blue Team efforts focused on visibility and monitoring through SIEM and log aggregation tools, organizational security practices such as multi-factor authentication and single sign-on, product security measures like third-party penetration testing and remediating vulnerabilities, Red Team efforts for internal penetration testing and identifying low-hanging fruit vulnerabilities, and insider threat mitigation. The author emphasizes that security doesn't have to be a big-company luxury and that small startups can benefit from implementing good security practices early on, even with limited resources. They also highlight the importance of partnerships between teams and finding a compromise to ensure security without sacrificing development or sales priorities.
Nov 22, 2023 2,283 words in the original blog post.
Zero trust is a security framework that eliminates implicit trust and considers it a vulnerability. It was first proposed in 1994 by Stephen Marsh but gained popularity in the 2010s. Despite its advantages, zero trust didn't take off due to practical realities and vendors' inability to clarify things. The term became a buzzword, and many vendors pushed partial solutions. However, with advancements like Wireguard, a simple and fast VPN that uses cutting-edge cryptography, zero trust is finally becoming achievable. NIST's guidance on zero trust architecture, big institutions pushing for it, and vendors catching up are also contributing to its practical implementation. Zero trust is returning to its roots as an architecture rather than a single purchase, and incident by incident, it will become inevitable as more organizations adopt it to prevent breaches and improve security.
Nov 15, 2023 2,233 words in the original blog post.
IPv6 is a network layer communications protocol that offers over 340 trillion IP addresses, making it virtually unlimited compared to IPv4's 4.3 billion addresses. The adoption of IPv6 has been slower than expected due to various factors such as the complexity of the new address format and the need for system administrators to maintain both protocols across their networks. However, with the widespread availability of devices and online services that use IP addresses, it is essential to consider deploying IPv6 to future-proof network infrastructure. The benefits of IPv6 include reduced costs, increased flexibility, and improved security through man-in-the-middle attack reduction. Despite some challenges, such as handling firewalls in IPv6 and configuring filter rules, the transition to IPv6 can be made with minimal disruption. By adopting IPv6, organizations can reduce their reliance on NAT firewalls, limit IP address sharing, and take advantage of the out-of-the-box nature of IPv6. With its vast number of available addresses, IPv6 is poised to become a common instrument in network toolkits, making it an attractive choice for those looking to future-proof their networks.
Nov 09, 2023 2,773 words in the original blog post.
We're celebrating our 1-year mark as Authentik Security, a company behind the open-source Identity Provider authentik, which unifies identity needs into a single platform replacing Okta, Active Directory, and auth0. We thank users, supporters, contributors, questioners, and testers for their past and present support. Our CTO, Jens Langhammer, started coding authentik in 2018 with the first commit on November 11. The project gained excitement around it in October 2021, catching eyes in the ecosystem. An Open Core Ventures approach led to funding and operational guidance, turning the project into a company in November 2022. We've released new features, including RBAC, our Enterprise version, and improved our CI/CD pipeline and deployment packaging testing. Our growing team has brought new ideas, processes, and expertise, but we're also learning to delegate and trust others. We celebrate our one-year mark with a focus on building features, supporting authentication protocols, and improving UX and ease-of-use. With several specific goals for the coming year, including increasing focus on UX, researching remote machine access and management, and implementing stronger integration and migration testing, we're excited to continue our journey with you.
Nov 01, 2023 1,572 words in the original blog post.