It’s already wise to establish a shared authentication word or phrase with family and colleagues, because AI can now convincingly mimic a person’s face, voice, gestures, even their gait during video calls or phone conversations. A bot won’t know the secret passcode when you ask for it. Within the next 20–25 years, you may need that same safeguard in face-to-face meetings, since Replicants will be lifelike enough to f…
OWASP Non-Human Identities Top 10
31–37 of 37 posts
Re: OWASP Non-Human Identities Top 10
#32It’s already wise to establish a shared authentication word or phrase with family and colleagues, because AI can now convincingly mimic a person’s face, voice, gestures, even their gait during video calls or phone conversations. A bot won’t know the secret passcode when you ask for it. Within the next 20–25 years, you may need that same safeguard in face-to-face meetings, since Replicants will be lifelike enough to f…
Please click through the link before commenting. NHIs have absolutely nothing to do with AIs masquerading as humans. This is basically about service accounts and API keys...
"Unlike human identities, NHIs are not controlled or directly owned by a human. Their identity object and authentication often work differently to human, and common human user security measures do not apply to them."
So this is about identities who are not human as they use those service accounts. Some would go as far as to say: AIs masquerading as humans.
Re: OWASP Non-Human Identities Top 10
#33Re: OWASP Non-Human Identities Top 10
#34I especially enjoyed NHI10:2025 Human Use of NHI. Time to stop all that pesky human use. Switch off the servers too, just to be sure.
Re: OWASP Non-Human Identities Top 10
#35Re: OWASP Non-Human Identities Top 10
#36Re: OWASP Non-Human Identities Top 10
#37I would love to hear about any useful work around leak/abuse-resistance improvements of service accounts and API keys (i.e. the 'NHI' referenced here -- awkward terminology!). Passkeys are a great solution when some kind of end-user interactivity is feasible, and AWS Secrets Manager is supposedly very good if you're entirely on that platform, but for self-hosting, the options seem limited (and things like Hashicorp V…