About this talk
This talk explores the crucial role of machine identity in zero trust environments, emphasizing its importance alongside human identity. Eviatar Gerzi, a principal security researcher at CyberArk, discusses the vulnerabilities in the trust assumptions of SPIFFE and SPIRE, commonly used for workload authentication in Kubernetes and cloud-native systems. The speaker demonstrates how attackers can exploit these identity models through techniques such as selector spoofing, overlapping identities, and SVID/key extraction, using the open-source tool Spooffe to illustrate how adversaries can impersonate workloads and move laterally across clusters. Attendees will gain insights into strengthening SPIRE deployments to defend against workload identity attacks.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56