Evan Gilman (@evan2645) 's Twitter Profile
Evan Gilman

@evan2645

Co-founder/CEO @spirl_inc, and @SPIFFEio + SPIRE maintainer. Co-author of Zero Trust Networks. ex-@pagerduty ex-@scytale_io ex-@VMware

ID: 790305186

calendar_today29-08-2012 22:50:59

464 Tweet

852 Followers

102 Following

Evan Gilman (@evan2645) 's Twitter Profile Photo

We have some amazing speakers lined up for SPIFFE Community Day next Friday 🙌🙌🙌 you should definitely attend if you're able to! Hybrid event, but in-person attendees in SF will have an unconference bit at the end 😀 see you there! …ecommunityday-fall2023.splashthat.com

Evan Gilman (@evan2645) 's Twitter Profile Photo

Last call for SPIFFE community day in-person attendees!! We'll cover all things workload identity, even some non-SPIFFE stuff 😁 see ya there!

Ryan Hurst (@rmhrisk) 's Twitter Profile Photo

In operating system design, the user context in which tasks operate is factored into the design to ensure the desired security properties. In application design, this consideration is often overlooked, with applications usually running as monolithic structures that are blindly

Christian Posta (@christianposta) 's Twitter Profile Photo

Using SPIFFE/SPIRE? Some systems like Istio have established conventions about how to encode identity with SPIFFE IDs, but you may be wondering how best to construct SPIFFE IDs… this is a GREAT blog from [email protected] // bsky.social 🖤🕯️ SPIRL spirl.com/blog/how-to-co…

SPIRL (@spirl_inc) 's Twitter Profile Photo

Are you working with SPIFFE and wondering what should go into your SPIFFE ID? Check out our post where we teach you what to consider for your IDs. buff.ly/41RUrIu

François Michel (@furanzu_) 's Twitter Profile Photo

SSH3 with ACME just naturally solves the classical Trust On First Use problem of SSH for VMs with hostnames such as Microsoft Azure VMs. Easily implemented in SSH3 v0.1.6 using Caddy Web Server's certmagic.✨ Native access to the HTTPS ecosystem in SSH is a real game changer, here's why:

SSH3 with ACME just naturally solves the classical Trust On First Use problem of SSH for VMs with hostnames such as <a href="/Azure/">Microsoft Azure</a> VMs.

Easily implemented in SSH3 v0.1.6 using <a href="/caddyserver/">Caddy Web Server</a>'s certmagic.✨

Native access to the HTTPS ecosystem in SSH is a real game changer, here's why:
Volkan Özçelik 🦌 (@vadidekivolkan) 's Twitter Profile Photo

📢 Join me this Friday at 8:00 AM PST! I'm excited to be a special guest on Whitney Lee’s livestream. We'll dive into the world of SPIFFE, SPIRE, and turtles 🐢⚡️. 📅 Mark your to Calendar to Enlighten⚡️: tanzu.vmware.com/developer/tv/e… #SPIFFE #SPIRE #ZeroTrust #Security #Tanzu

Volkan Özçelik 🦌 (@vadidekivolkan) 's Twitter Profile Photo

Psst… In case you want to hear me ranting for two hours about secrets, SPIFFE, SPIRE, Turtles, passport, piano, kids, teenagers, and Neurology this is the video recording of today’s Enlightning » youtube.com/watch?v=EB6AJT…

Ryan Hurst (@rmhrisk) 's Twitter Profile Photo

It is 2024 will wouldn't be rolling out new systems using passwords and no MFA would you? Of course not -- It is probably time to rethink the way you do your workload and machine authentication too.

SPIFFE (@spiffeio) 's Twitter Profile Photo

In case you missed the SPIFFE Virtual meetup last month, here are the recordings. Thank you to presenters from Coinbase, Indeed, and HPE for sharing their insights and experiences youtube.com/playlist?list=… #SPIFFE #ZeroTrust

CloudSecurityPodcast (@cloudsecpodcast) 's Twitter Profile Photo

Episode 166 "Workload Identity, Zero Trust and #SPIFFE (Also Turtles!)" of Cloud Security Podcast where hosts Dr. Anton Chuvakin and Timothy Peacock interview Evan Gilman (Evan Gilman) and Eli Nesterov (꩜ Eli Nesterov), co-founders SPIRL about identities cloud.withgoogle.com/cloudsecurity/…

Episode 166 "Workload Identity, Zero Trust and #SPIFFE (Also Turtles!)" of Cloud Security Podcast where hosts <a href="/anton_chuvakin/">Dr. Anton Chuvakin</a> and <a href="/_TimPeacock/">Timothy Peacock</a> interview Evan Gilman (<a href="/evan2645/">Evan Gilman</a>) and Eli Nesterov (<a href="/elinesterov/">꩜ Eli Nesterov</a>), co-founders <a href="/spirl_inc/">SPIRL</a> about identities cloud.withgoogle.com/cloudsecurity/…
Evan Gilman (@evan2645) 's Twitter Profile Photo

Wrote this short post yesterday on why multi-factor auth for machines in the form of hardware/software attestation is so important. Lots and lots of breaches involving single factor creds like service account etc...

Ryan Hurst (@rmhrisk) 's Twitter Profile Photo

Put some thoughts together on how to think about ACME and SPIFFE. The TL;DR is: ACME is about proving control of an identifier, while SPIFFE is about assigning and managing identifiers dynamically to enable the authorization of the subjects of those identifiers.

Evan Gilman (@evan2645) 's Twitter Profile Photo

If you're in Seattle for Cloud Native Security Con, come hang out tonight for some bites and good times .. all things workload identity! What is there not to love? See you there!

Tal Be'ery (@talbeerysec) 's Twitter Profile Photo

Pass-the-{token} attacks are still very much relevant. Tokens may change: Cookie, NT Hash, Kerberos ticket, MFA token, ... However, the problem is not in the "token" but in the "pass". We need a solutions to make tokens stay put, such as device and channel binding.

SPIRL (@spirl_inc) 's Twitter Profile Photo

The potential of AI agents should not make us forget that we already have the tools needed to secure them. Just follow the advice of an 11th-century monk, and "start by doing what's necessary." Read more in Pieter Kasselman's blog hubs.li/Q037pyqT0 #AI #AISecurity #identity