June 2024 Summaries

2 posts from Authentik Security

Filter
Month: Year:
Post Summaries Back to Blog
Authentik is an open source Identity Provider that aims to unify identity needs into a single platform, replacing traditional solutions like Okta and Active Directory. The XZ backdoor incident highlighted the importance of transparency in open source security products, as it was caught by the community due to being open-source. This approach provides visibility into code, owners, and changes, making it harder for attackers to exploit vulnerabilities. In contrast, proprietary solutions lack this transparency, making it difficult for users to trust their identity management systems. Authentik Security is built on top of authentik, with both the enterprise version and source code available, ensuring transparency by default. This approach also aligns company and community incentives, as the business has a clear financial incentive to support the open source project. By building in the open, Authentik can operate transparently, define clear standards around documentation and communication, and publish the results of pen tests, providing security benefits for users and customers. However, relying on community-maintained projects also comes with risk, as seen in the XZ project's vulnerability due to a lack of dedicated staff. To mitigate this risk, open core models can provide a middle ground between business ownership and community involvement. By maintaining an open source project, Authentik can build trust with its users, attract top talent, and continue to develop its security features through transparency and collaboration.
Jun 27, 2024 1,511 words in the original blog post.
As a founding security engineer at Authentik Security, an open-source Identity Provider, you're likely inheriting established security practices and high stakes, with the SolarWinds story serving as a cautionary tale. To prove your value, focus on getting the lay of the land by assessing the current state of security, understanding the company's security stack, and identifying areas for improvement. Start with what you're good at, such as phishing awareness training and access management, and build your knowledge in other areas as you go. Implementing Single Sign-On (SSO) can automate onboarding and offboarding, improve workflows, and reduce friction. Documenting processes and building relationships with teammates are also crucial. Don't be afraid to dig into code and challenge developers to ensure security is prioritized. Finally, pick the hill you want to die on, focusing on activities that have an impact without generating excessive work for others.
Jun 11, 2024 2,015 words in the original blog post.