Can We Really Have Zero Trust with a Federated Identity Architecture? With Justin Richer (MongoDB)
Identi31 Jun

Can We Really Have Zero Trust with a Federated Identity Architecture? With Justin Richer (MongoDB)

Most organizations say they are doing Zero Trust. Many still trust their IAM directory implicitly, protect it with a firewall, and call that a modern identity architecture. That is a perimeter by another name. In this session, Agne Caunt (Dock Labs), Richard Esplin (Dock Labs) and Justin Richer (MongoDB) work through what Zero Trust actually requires at the identity layer, why federated architectures tend to recreate the problems they were designed to solve, and what a more structurally sound approach looks like.

0:00 Introduction and guest overview

3:48 Zero Trust: origins and core principles

10:26 Why Zero Trust is still unnatural

11:45 Zero Trust in what? The foundational question

13:14 Directory synchronization: how enterprise identity fragility compounds

15:47 Verifiable credentials and the move to user wallets

18:06 Is the wallet really untrusted? Justin pushes back

20:39 Practical transition: using wallets at domain boundaries, not everywhere

22:55 VCs as a reinvention of X.509 for an online world

26:22 Tool comparison: OAuth/OIDC/SAML + SCIM vs. VCs

27:42 Shared Signals and Events (SSE): strengths and structural limits

31:51 User Managed Access (UMA): what it got right, why it stalled

34:35 GNAP: what it solves, when to use it instead of OAuth

41:00 SPIFFE/SPIRE: workload identity and short-lived credentials

46:06 SPIFFE's trust model and the "bottom turtle" question

47:24 WIMSE: bridging workload identity across trust domains

51:12 Agentic identity: the question from the audience

52:38 AI agents -- neither human nor workload, and why that matters

55:26 "On behalf of" vs. "for the benefit of" -- the liability distinction

58:55 What would a Zero Trust native architecture actually look like?

Website - https://www.dock.io/

LinkedIn - https://www.linkedin.com/company/docknetwork/

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(69)

Trusted Caller Identity: Pilot Results from GSMA & Telefónica [Live]

Trusted Caller Identity: Pilot Results from GSMA & Telefónica [Live]

This session presents the results of a six-month proof of concept run by Telefónica Tech, GSMA, Dock Labs, and TMT ID to rebuild call center authentication using mobile network APIs and verifiable cre...

18 Mai 59min

Identity Web Wallet Demo: Enable Reusable Digital ID Without a Mobile App [Live Demo]

Identity Web Wallet Demo: Enable Reusable Digital ID Without a Mobile App [Live Demo]

In a recent webinar, Richard Esplin, Head of Product at Dock Labs, and Agne Caunt, Product Owner, walked through a live demo of our new browser-based approach to digital identity.Through a step-by-ste...

20 Apr 56min

AI Meets Digital ID: Credential Issuance and Verification using MCP [Live Demo]

AI Meets Digital ID: Credential Issuance and Verification using MCP [Live Demo]

AI agents are quickly moving from experimentation to real-world deployment, but one critical question remains: how do you establish trust when agents start acting on behalf of users?In a recent webina...

30 Mar 54min

From Federation Sprawl to Unified Identity: How to Make Verified Identity Reusable Across Systems

From Federation Sprawl to Unified Identity: How to Make Verified Identity Reusable Across Systems

Identity fragmentation isn’t usually the result of bad architecture. It’s the natural byproduct of growth. New apps get added. Business units operate independently. Acquisitions bring in new identity ...

2 Mar 49min

Inside World ID: How "Proof of Human" Works [Live Event]

Inside World ID: How "Proof of Human" Works [Live Event]

AI agents are rapidly changing the shape of the internet. What started as an effort to keep bots out is quickly becoming a much more complex challenge: distinguishing humans from machines, enabling sa...

23 Feb 1h

How EUDI Wallets Will Impact Payments and Banking [Live Event]

How EUDI Wallets Will Impact Payments and Banking [Live Event]

As Europe moves closer to rolling out the European Digital Identity Wallet, questions are shifting from if to how, and what this really means for banking, payments, and trust online. In a recent live ...

2 Feb 58min

The Future of Caller Authentication: GSMA and Telefónica Reveal the Trusted Caller Identity Pilot

The Future of Caller Authentication: GSMA and Telefónica Reveal the Trusted Caller Identity Pilot

To explore what a better model could look like, Dock Labs hosted a live webinar on the future of caller authentication, presenting a joint proof of concept developed with GSMA Telefónica Tech and TMT ...

19 Jan 56min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
tomprat-med-gunnar-tjomlid
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
hans-petter-og-co
shifter
pedagogisk-intelligens
rss-anleggspraten
fornybaren
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-plateprat
rss-ai-forklart
rss-ki-praten
plattformpodden
rss-devops
rss-30-minutter-inn-i-fremtiden