youtube.com
GitLab's Email Is a Skeleton Key?
GitLab's private issue-email address hides a non-expiring, account-wide token that bypasses IP restrictions and two-factor authentication, as discovered by Aikido Security. The panel does not hold back in their response. Dmitriy Sokolovskiy makes the case for treating it as part of your non-human identity program while Christian Frösch flags the configuration drift risk, and Rich lands the perfect "secure by design" punchline. Is there a token like this lurking in your environment right now? Big thanks to our sponsor, Nudge Security!
Join us next time — LIVE every Friday at 4 PM ET / 1 PM PT: https://youtube.com/live/nYDGmB7Luvs?feature=share
#cybersecurity #cybersecuritynews #infosec #news #informationsecurity