anderseknert, to devops
@anderseknert@hachyderm.io avatar

It's been a month since the last release, but v0.22.0 of everyone's favorite linter, , is now out!

Featuring 3 new linter rules, language server support for code completion, and much more. Check out the release notes, and get your copy here!

https://github.com/StyraInc/regal/releases/tag/v0.22.0

fusiondirectory, to opensource French
@fusiondirectory@pouet.chapril.org avatar

FusionDirectory a un nouveau site web 🍾🍾🍾 on se projette dans les 10 prochaines années avec un look plus moderne qui met en avant notre expertise, nos services autour de la gestion des identités

ltb_project, to php French
@ltb_project@floss.social avatar

🎉 LDAP Tool Box Self Service Password 1.6 released!

➡️ https://projects.ow2.org/view/ldaptoolbox/ltb-self-service-password-1-6-0-released/

📃 A lot of new features like entropy bar, dynamic checks and mail/phone attributes modification

:php: @ow2 @worteks_com

julie, to Cybersecurity

Security folks, I need some help. My wife is looking for a job after taking a few years off to take care of the kids and she's having a hard time finding legit security opportunities. And the legit ones she does find don't like the gap in her resume.

If you have or know of any legit remote openings for someone with experience in identity and access management, can you please share?

She has her CISSP and while most of her experience is in IAM she's willing to branch out and learn a new specialty. She also happens to be both the faster learner and the smarter one of the two of us!

Boosts greatly appreciated!

simplenomad, to security
@simplenomad@rigor-mortis.nmrc.org avatar

My employer is hiring, specifically in the Security division. Security Identity Management is the area, so if you're into and and you're qualified, apply. If not, a few other positions are available, feel free to poke around. Fully remote. I'm not shopping for a referral, I'm shopping for a work colleague, so apply!

https://boards.greenhouse.io/gitlab/jobs/7294564002

anderseknert, to random
@anderseknert@hachyderm.io avatar

Apps that will only present the #2FA challenge upon a successful password #authentication — isn’t there a very good point in always providing both, as to not give any hints on whether the first factor credentials were correct or not?

#iam #identity

renegadejade, to Cybersecurity
@renegadejade@hachyderm.io avatar

What’s your favorite identity management tool for a non-profit with limited budget but ~40,000 identities and growing to manage? We’re already talking to Okta.

Boosts welcome, especially into infosec.exchange

bohwaz, to random French
@bohwaz@mamot.fr avatar

, le gars d', est complètement tombé dans les thèses complotistes, et ça ne date pas d'hier. Dans "C'est clair je suis sombre" de 1998 (sur l'École du Micro d'Argent) il disait déjà :

« Je suis sceptique quand on me parle de Sida
Ce serait un produit de laboratoire que ça ne m'étonnerait pas
On appelle ça régulation, moyen d'élimination, de la surpopulation (...)
Le vaccin, ils l'ont sûrement déjà découvert
Ou la commercialisation est une histoire de gros sous »

fusiondirectory, to opensource French
@fusiondirectory@pouet.chapril.org avatar

@fusiondirectory is happy to be again at the wednesday 6 march at if you want to be part of a small company that redefine with free software 😉 come talk to us 😎

https://opensourcejobfair.be

@ulyssis

0x58, to AWS

📺 One to watch today - Interesting @frichetten talk titled "Evading Logging in the Cloud: Bypassing AWS CloudTrail" :cloudcomputing:​

https://youtu.be/YP2XNAbB_Nw?si=mLK1z_fh8MZkgsVG

worteks_com, to opensource French
@worteks_com@mastodon.social avatar

💻 Vous ne pouviez pas être au FOSDEM ? Retrouvez la conférence FusionIAM, a full Open Source Identity & Access Management solution, sur notre site !

➡️ https://www.worteks.com/opensource/conferences/2024-02-04-fosdem-fusioniam-full-open-source-identity-access-management-solution/

@ow2

clementoudot, to opensource French
@clementoudot@framapiaf.org avatar

Thanks to @fosdem organizers, the video of my taks about FusionIAM (a full Open Source Identity & Access Management solution) is now online: https://video.fosdem.org/2024/k3401/fosdem-2024-1939-fusioniam-a-full-open-source-identity-access-management-solution.av1.webm

lemonldapng, to overwatch French
anderseknert, to devops
@anderseknert@hachyderm.io avatar

I just published v0.16.0. This release brings two new linter rules, but most importantly it adds a language server (LSP) mode to Regal, allowing editor integrations to lint your workspace continuously as you work on your policies. Client implementations soon to follow. Exciting times!

Thanks @charlieegan3 for an awesome contribution!

https://github.com/StyraInc/regal/releases/tag/v0.16.0

worteks_com, to opensource French
@worteks_com@mastodon.social avatar
hertg, to security

Question for the #identity and #authentication people.

For user accounts that have enabled multifactor authentication, how do you handle self-service password resets? On online platforms, it is usually possible to reset the password via email. I think that is fine for accounts that don't use multifactor authentication. But what if a user logs in with their phone number (They have no email, just the phone) and use text message as their second factor? Sending a password reset code via text message would be a bit stupid. This would mean that the user doesn't really have two-factor authentication if you can reset the first-factor with the second-factor.

I do currently not allow self-service password resets if a user has multifactor enabled. They are required to get in contact with customer support in that case. For our use-case this is ok, but it's obviously not very user-friendly. However, I don't really see a solution in the case where the phone number is the primary identifier and second-factor. I am interested in some thoughts on the topic.

#iam #openid #oauth2 #security

kubikpixel, to random German
@kubikpixel@chaos.social avatar

Ich weiss, das zu mindestens mal unsicher war, doch wie sieht es bei den anderen aus und nutzen die auch die aktuellste für ihre 'en? Das ist ja viel versprochen aber nicht garantiert, da Closedsource oder nicht?

« & Management – Die 9 besten IAM-Tools:
Diese Identity-und-Access-Management () -Tools schützen Ihre Unternehmens-Assets auf dem Weg in die Zero-Trust-Zukunft.»

🔐 https://www.csoonline.com/de/a/die-9-besten-iam-tools,3673918

anderseknert, to devops
@anderseknert@hachyderm.io avatar

Me and @charlieegan3 have been working on a new guide for the most common errors seen in during policy development. Parser errors, compiler errors and evaluation errors — it's all in there. Hopefully it'll be a useful resource to anyone trying to get a better understanding on why some errors happen, and how to fix them. Feedback always welcome!

https://docs.styra.com/opa/errors

frankel, to random
@frankel@mastodon.top avatar

's Policy as Code Report: Identity and Access Management Drives Adoption

https://www.infoq.com/news/2023/12/styra-policy-as-code-report/

lemonldapng, to overwatch French
hertg, to random

When implementing on an Identity Provider's side. Where exactly should one draw the line between and ? I see that most platforms make a distinction between those. Can anyone link me some article or blog post on this topic? If I were to implement security key and passkey support on a provider that does not yet support any WebAuthn, should I go down the same route?

My current assumption is that during passkey registration you'd set "residentKey = required" and "userVerification = required", whereas for a security key you'd set "residentKey = discouraged" and "userVerification = preferred".

Also, I'm assuming that a security key can also function as a form of multi-factor authentication if UV was true during registration AND authentication. Obviously without the neat part of Passkeys where you don't have to manually enter the username.

anderseknert, to devops
@anderseknert@hachyderm.io avatar

Regal v0.14.0 just released! 🎉 The latest edition of the community's favorite linter features two new rules, a new output format, and many improvements and fixes. Release notes and downloads here: https://github.com/StyraInc/regal/releases/tag/v0.14.0

anderseknert, to devops
@anderseknert@hachyderm.io avatar

Regal v0.13.0 just released! Featuring 3 new linter rules, performance improvements across the board, and many improvements and fixes. If you're working with and in any way, make sure to try it out! Regal aims to help not just by finding bugs and issues, but to teach developers of all levels idiomatic Rego.

I'd love to hear what you think!

https://github.com/StyraInc/regal/releases/tag/v0.13.0

damienbod, to dotnet
paulsanders, to selfhosted

Does anyone know a decent ? Complete overkill I know… but don’t really want to spin up an tenant for basic at home and cloud services.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • Youngstown
  • mdbf
  • rosin
  • slotface
  • InstantRegret
  • khanakhh
  • Durango
  • kavyap
  • osvaldo12
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • ngwrru68w68
  • everett
  • tester
  • ethstaker
  • cisconetworking
  • cubers
  • modclub
  • provamag3
  • anitta
  • normalnudes
  • Leos
  • lostlight
  • All magazines