Skip to content

Identity

Information used to distinguish one entity (person, device, or application) from another. In security, identity is the basis for Authentication (who are you?) and Authorization (what can you do?).

Impact

Identity is the new perimeter. In a cloud/mobile world, firewalls are porous. Identity is the only constant control point.

Weinto take

We treat Machine Identity as critically as Human Identity. A server should have an identity (like a SPIFFE ID) and present a certificate to talk to another server. Hardcoded API keys are the "password on a post-it note" of the cloud era—unacceptable.