Are We There Yet? The Cloud Identity Trap
We set out to make a simple video about hardening logins. Instead, we discovered how deeply broken our cloud identity model has become.
From passkeys that quietly bypass your second factor, to “Sign in with Google” giving providers authority across dozens of sites, the convenience we’ve embraced has created massive single points of failure.
In this video I walk through real account takeover cases, the limitations of current passkey revocation, and a practical compartmentalization strategy to limit blast radius when (not if) something goes wrong.
Chapters below
00:00 - Intro
00:22 - Problem
01:53 - 2FA
02:30 - MFA
02:51 - passkey
04:22 - What is 2FA Suppose to Mean?
05:01 - Revoking a passkey
05:20 - Login in AS ...
06:14 - The Cloud Trap
07:20 - Best Practices
07:37 - Simple Best Practices
08:10 - Oh and one more thing
10:54 - Closing
DJ Ware
I would like to use this channel to give back to the community what I have learned from others. I cover a wide range of topics on computing technology from Home Server setup on a budget, Linux for general use (workstation, server and development), High P...