OWASP Non-Human Identities Top 10
owasp.org
OWASP Non-Human Identities Top 10
1–10 of 37 posts
Re: OWASP Non-Human Identities Top 10
#2Re: OWASP Non-Human Identities Top 10
#3Re: OWASP Non-Human Identities Top 10
#4They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.
The collection provides a structured approach to self audit the security practice regarding non-human identities. The recent CCC showcased breach of a VW connected car repository based on the exploitation of those NHI.
Re: OWASP Non-Human Identities Top 10
#5This comprehensive list highlights the most critical challenges in integrating Non-Human Identities (NHIs) into the development lifecycle, ranked based on exploitability, prevalence, detectability, and impact.
Re: OWASP Non-Human Identities Top 10
#6Re: OWASP Non-Human Identities Top 10
#7Based on the title and the first few paragraphs, I expected this to be about risk of datacenter security breaches by Bears, and the like.
Re: OWASP Non-Human Identities Top 10
#8They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.
I only known service accounts, which pose similar threat. Both AI and Humans can use service accounts and api-keys to pose the same threats.
But it's ultimately known and wide-spread as service accounts from what I know. Is non-human identity referring to a special case or attack vector?
Re: OWASP Non-Human Identities Top 10
#9Re: OWASP Non-Human Identities Top 10
#10They are using some fancy wording, but this just seems to be about regular service accounts (i.e. "bots") when they are mixed with user accounts in a SoA setting. No AI needed.
AI is not mentioned. Besides, service accounts are not bots. The collection provides a structured approach to self audit the security practice regarding non-human identities. The recent CCC showcased breach of a VW connected car repository based on the exploitation of those NHI.