"GCP Primitive Roles, An indictment" - Kat Traxler
fwd:cloudsec
0:00 / 0:00
"GCP Primitive Roles, An indictment" - Kat Traxler
675 просмотров · 6 лет назад
fwd:cloudsec
5,3 тыс. подписчиков
675 просмотров · 6 лет назад
GCP Primitive Roles, An indictment
Speaker: Kat Traxler
Kat Traxler is a Security Professional in the Twin Cities performing penetration testing, security architecture and research in the areas of Web Security, IAM, Payment Technologies and Cloud Native Technologies.
Kat Traxler is obsessed with the attack surface at the confluence of Identity and Cloud Platform APIs and thinks you should be too.
Abstract:
Before Google Cloud released Cloud IAM there was only Primitive Roles. Prior to 2016, the course-grained Roles, Owner, Editor and Viewer were the only mechanisms available to grant access to GCP resources.
Primitive Roles are the antithesis to least privilege but more specifically, they’re mere existence significantly impacts the security posture of a GCP Project. Four years after the release of Cloud IAM, despite the availability of fine-grained Roles, Primitive Roles are still pervasive in GCP. Is it possible to eradicate Primitive Roles from your GCP Organization and still use the Platform?