SecuriTEA & Crumpets is a series where security professionals come together to talk about their background, research, and interesting topics. The eight episode is with Andy Li who is a Security Engineer at Segment. He has interned at companies such as Bouncer and Amazon, he completed a Computer Science Degree at UCDavis. Recently at Segment Andy has been involved with access service which allows developers to access resources in the cloud which we dive into this episode!
00:00 Intro
01:10 University Background
01:22 Computer Science Degree
03:30 Security classes at University?
07:00 Obtaining internships
10:36 Contrast between working at a start-up vs Amazon
13:30 What do you wish you knew when you transitioned from Computer Science to Security?
15:10 What is boxer? (Preventing fraud with credit card scanning)
18:32 What do you do at Segment?
19:30 Access Service
20:39 Common pitfalls to Overprovisioned and Underprovisioned access
25:39 Benefits to mapping Okta to AWS
28:23 Mapping to SaaS apps / SCIM
30:09 Boggs Getting Bogged Down
32:12 How difficult or complex is it for organizations to approach least privilege?
34:00 Benefits of moving to Access Service
35:30 Designated approvers with most context
36:08 Temporary access (Time based and Activity based)
38:30 What were the technical challenges around Access Service?
42:20 How do you think Access Service has changed the security landscape?
44:50 Future Work (Policies and Dynamic Roles)
47:05 Core things to think about when building Access Service
References:
https://www.usenix.org/conference/use...
https://segment.com/blog/access-service/
https://cloud.google.com/beyondcorp