Live data from Hacker News

OWASP Non-Human Identities Top 10

owasp.org

1–10 of 37 posts

Re: OWASP Non-Human Identities Top 10

#4
post #2

They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.

AI is not mentioned. Besides, service accounts are not bots.

The collection provides a structured approach to self audit the security practice regarding non-human identities. The recent CCC showcased breach of a VW connected car repository based on the exploitation of those NHI.

Re: OWASP Non-Human Identities Top 10

#5
Full title is "OWASP Non-Human Identities Top 10".

This comprehensive list highlights the most critical challenges in integrating Non-Human Identities (NHIs) into the development lifecycle, ranked based on exploitability, prevalence, detectability, and impact.

Re: OWASP Non-Human Identities Top 10

#7

Based on the title and the first few paragraphs, I expected this to be about risk of datacenter security breaches by Bears, and the like.

Mice and ants are listed as some of the greater enemies of the datacenter according to a pest control company's website. I guess bees would cause some inconvenience too.

Re: OWASP Non-Human Identities Top 10

#8
post #2

They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.

I am confused with the wording. Is there an official description of Non-Human Identities?

I only known service accounts, which pose similar threat. Both AI and Humans can use service accounts and api-keys to pose the same threats.

But it's ultimately known and wide-spread as service accounts from what I know. Is non-human identity referring to a special case or attack vector?

Re: OWASP Non-Human Identities Top 10

#10
post #2

They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.

AI is not mentioned. Besides, service accounts are not bots. The collection provides a structured approach to self audit the security practice regarding non-human identities. The recent CCC showcased breach of a VW connected car repository based on the exploitation of those NHI.

I agree. A bot is a program or an application that provides some sort of functionality that appears automated or autonomous in some way. A service account could be the primary identity of a bot, but that doesn't make it a bot.
Post reply on HN