with-agents

Security

Security engineering across cloud, applications, identity, data, threat response, governance, and compliance.

Topics

Showing 10 resources

Resources

Better Auth Security

Article

A review point for a fast-moving TypeScript authentication framework's controls and trade-offs

A mutable implementation reference for Better Auth's password hashing, secret rotation, sessions, CSRF and redirect defenses, cookies, OAuth state and PKCE, rate limiting, proxy trust, and outbound requests. Use it to assess framework configuration, not as a substitute for OAuth, OIDC, or WebAuthn standards.

Better AuthAug 29, 2026
Identity & accessApplication security

Configure Workload Identity Federation with deployment pipelines

Article

Keyless authentication from external CI/CD systems to Google Cloud

A practical guide to exchanging deployment-platform OIDC tokens for short-lived Google Cloud credentials with explicit admission and IAM controls.

Google CloudAug 28, 2026
Google CloudCloud security

Best practices for using Workload Identity Federation

Article

Trust, least-privilege, and audit controls for external workloads

Google's security guidance for hardening federated workload trust against spoofing, privilege escalation, weak audit trails, and malicious credential configurations.

Google CloudAug 28, 2026
Google CloudCloud security

Enterprise foundations blueprint

Article

A Terraform-backed baseline for enterprise governance and security

Google's reference foundation for consistent resource hierarchy, identity, networking, logging, policy, secrets, keys, and threat detection at enterprise scale.

Google CloudMay 15, 2025
Google CloudCloud security

RFC 9700: Best Current Practice for OAuth 2.0 Security

Article

Current OAuth deployment requirements for redirect flows, tokens, clients, and proxies

The IETF's OAuth 2.0 Security Best Current Practice updates the original framework's threat model and deployment advice. It requires or recommends stricter redirect handling, PKCE, replay defenses, token privilege restriction, secure client authentication, and hardened proxy boundaries while deprecating weaker grants and response modes.

RFC EditorJan 30, 2025
Identity & accessApplication security

OpenID Connect Core 1.0 incorporating errata set 2

Article

The normative identity layer over OAuth 2.0 and its token-validation contract

OpenID Connect Core defines authentication over OAuth 2.0 using signed ID Tokens and, optionally, UserInfo. It specifies flows, claims, subject identifiers, discovery relationships, and relying-party validation, but its historic implicit and hybrid flows need constraints from current OAuth security guidance.

OpenID FoundationDec 15, 2023
Identity & access

OWASP API Security Top 10 — 2023

Article

A practical risk taxonomy for API authorization, business logic, resources, inventory, and dependencies

OWASP's second API Security Top 10 is an awareness and threat-modeling taxonomy, not an implementation standard. Its ten risk families connect object, property, and function authorization with authentication, resource consumption, business-flow abuse, SSRF, configuration, inventory, and third-party API trust.

OWASP FoundationJun 5, 2023
Application securityIdentity & accessData protectionThreat detection

Cloud Security Basics

Playlist

Shared responsibility, identity, data, platform, logging, and audit foundations

Ten reviewed Google Cloud Tech episodes on shared responsibility, access and data risks, platform and hardware controls, IAM, service accounts, security logging, and audit logs. The 2020–2021 product roles, defaults, interfaces, and procedures are historical context; current Google Cloud documentation remains the authority for implementation.

Google Cloud TechLatest summary: Jul 3, 2021
Google CloudCloud security

Web Authentication: An API for accessing Public Key Credentials Level 2

Article

The stable W3C baseline for origin-bound public-key registration and authentication

The W3C Recommendation defines the browser and relying-party contract for registering and using origin-bound public-key credentials. It is the stable normative baseline for WebAuthn ceremonies, server verification, authenticator data, user presence and verification, attestation, privacy, and security considerations.

World Wide Web Consortium (W3C)Apr 8, 2021
Identity & accessApplication security

Getting Started with Cloud Security Command Center

Playlist

Five historical walkthroughs of scanning, detection, data protection, and security posture

Five reviewed 2019 walkthroughs covering Cloud Security Scanner, anomaly detection, Event Threat Detection, data-loss prevention, and Security Health Analytics. Use the collection to understand the detection and posture-management boundaries, not as current guidance for product editions, roles, detectors, interfaces, or remediation steps.

Google Cloud TechLatest summary: Oct 23, 2019
Google CloudCloud security