Sign in

Oblique

@oblique.security
32 followers 5 following 35 posts

Scale access securely and automatically

PostsRepliesMedia
Oblique @oblique.security · 27/08/2026
By limiting "sign in with Google" permissions, you can control what apps users access, and what OAuth grants they give those apps. You shouldn't block sign in — users will find another way — but you can block additional OAuth grants. More in our blog post: oblique.security/blog/unconfi...
oblique.security
The wrong way to block "Sign in with Google" | Oblique
You can block your users from signing into apps with their Google account, and granting access to their inbox. But not knowing what they're using is worse.
000
Oblique @oblique.security · 19/08/2026
Our co-founder @ericchiang.bsky.social had fun with Claude finding vulns in SAML implementations. Using a hacking harness, what he found was full authentication bypasses in multiple libraries, tired maintainers, and AI-automated fixes. oblique.security/blog/hacking...
oblique.security
Hacking SAML with Claude Code | Oblique
After many years of complaining about how insecure SAML is, I decided to try to prove it by using Claude Code to hack every SAML implementation I could find.
000
Oblique @oblique.security · 28/07/2026
We recently completed our first SOC 2 Type II audit, covering the Security and Confidentiality trust services criteria. Our cofounder @mayakaczorowski.com shares what's still hard: manual access reviews, scattered evidence, and complying with bygone requirements: oblique.security/blog/soc2-re...
oblique.security
What's still annoying about SOC 2 in 2026 | Oblique
We completed our first SOC 2 audit. We still suffered through manual access reviews, scattered evidence, and proving compliance with bygone requirements.
000
Oblique @oblique.security · 05/05/2026
Our background jobs were inexplicably slow. We looked at existing tracing, added OTel, and hypothesized. It looked like a database problem: multi-second SQL queries, connection pool exhaustion, lock contention candidates. The fix that @jbrandhorst.com found turned out to be one line of YAML 😅
011
Oblique @oblique.security · 30/04/2026
A coworker disappearing into a cave and coming back with 12,000 lines of code you have to review is cause for a heart attack. But, how do you handle the ever-increasing volume of code reviews? Our engineering team wrote down how we navigate code reviews at Oblique: oblique.security/blog/how-obl...
oblique.security
How Oblique handles code review etiquette | Oblique
Code reviews aren’t just about ensuring engineering quality, they’re also about building team culture. Focus on communication and understanding rather than nit-picking style quirks.
052
Oblique @oblique.security · 06/04/2026
Great security doesn't have to cost a lot. Our security stack costs us nothing. By using free tiers or open-source versions of popular tools (Semgrep, Truffle, RunReveal, and Sublime), we're doing more than just checking a box. @mayakaczorowski.com gives an overview: oblique.security/blog/securit...
oblique.security
The $0 security stack | Oblique
As part of our initial SOC2 audit, we wanted to put in place actually useful security tools. Luckily, in 2026, world-class security costs literally nothing.
020
Oblique @oblique.security · 19/02/2026
Access controls should map to how your organization works — not the other way around. Organizations generally grant access based on department, based on reporting chain, and based on projects. Use what works for your org. oblique.security/blog/org-str...
oblique.security
Fit access controls to your org, not the other way around | Oblique
Groups used for access controls can be based on department, reporting chain, or projects. The right answer is whatever maps best to how your org actually works.
000
Oblique @oblique.security · 13/02/2026
Our engineering team is cooking 🍳 and sharing great tidbits recently that you might have missed 🧵
121
Oblique @oblique.security · 11/02/2026
In other parts of security, we’ve learned that fixing classes of problems is the only way we can address them for good — but we haven’t had that mindset shift yet in access management. We need better controls, so that we can get to fewer tickets, not faster tickets. oblique.security/blog/access-...
oblique.security
Access requests are a bandaid, not a fix | Oblique
IT teams are overwhelmed with never-ending access requests. Getting off the identity treadmill means getting to fewer tickets over time, not faster tickets.
021
Oblique @oblique.security · 08/12/2025
It’s 2025 and many teams still can’t reliably enforce strong authentication across their app stack. That’s the real SSO tax: not paying to have SSO, but paying to enforce it. Read more about how we’re approaching practical enforcement at Oblique: oblique.security/blog/real-ss...
oblique.security
The real SSO tax | Oblique
The SSO tax shouldn't be about having SSO — it should be about enforcing it. The value of SSO is to centrally manage access and require strong authentication.
010
Oblique @oblique.security · 07/11/2025
What you really want to control access to is data, not systems — so why are we stuck thinking in systems? Our cofounder @mayakaczorowski.com shares what she learned researching tiered controls for our latest report on Modern Access Controls.
110
Oblique @oblique.security · 15/10/2025
Authentication failures from the last five years at Okta, Snowflake, and Twitter show very similar attacks, from credential theft, to MFA bypass, to session hijacking. Dive deeper into these incidents and avoid repeating the same mistakes: oblique.security/blog/authn-f...
oblique.security
What we can learn from real-world authentication failures | Oblique
Recent breaches at Okta, Snowflake, and Twitter help us learn how to prevent authentication failures like credential theft, MFA bypass, and session hijacking.
000
Oblique @oblique.security · 07/10/2025
Don't rely on managers for access approvals — they don't work, for either security or speed. Instead, get approvals from app owners who actually understand the systems and risks, and automate approvals that are always granted.
100
Oblique @oblique.security · 07/10/2025
We see it all the time: internal security tools “work” but hurt to use—so people route around them. We break down why teams underinvest in UX and how to build tools users actually adopt. Treat security like a product. oblique.security/blog/security-ux
000
Oblique @oblique.security · 03/10/2025
We interviewed IT and security teams on what actually works in access control: shared ownership, data-first controls, enforce at change time, route approvals to app owners or automate, pre-approved groups for JIT access. oblique.security/blog/policies-repo…
000
Oblique @oblique.security · 24/09/2025
What *really* works in access control? We asked modern IT and security teams how they define and improve their policies — in reality, not in theory. Read the report: oblique.security/blog/policie...
oblique.security
Modern access controls: takeaways on what actually works | Oblique
We interviewed IT and security teams to ask them how they actually define, implement, and improve their access control policies. Get the report to learn more.
000
Oblique @oblique.security · 17/09/2025
The biggest scaling challenge for IT and security teams isn't technical — it's organizational. When you're managing access for thousands of employees and hundreds of applications, you need to know: who owns what? Read more in our latest post: oblique.security/blog/delegat...
oblique.security
Delegate authority to those with context | Oblique
Business teams have context for access decisions but lack authority. Delegate to those closest to the resources by defining clear ownership for each app.
000
Oblique @oblique.security · 10/09/2025
You shouldn't build your internal tools in git unless you hate your users. Stop making me learn git. Stop trying to make git happen 💁‍♀️ oblique.security/blog/git-int...
oblique.security
Stop trying to make git happen | Oblique
Internal tools built as code come with version control and audit logs for free, but git becomes a barrier for non-engineers to use these tools.
000
Oblique @oblique.security · 04/09/2025
If you're interested in learning more about what's happening in the IAM market — and who's competing with Okta and why — then you should read our cofounder @mayakaczorowski.com's latest post.
000
Oblique @oblique.security · 02/09/2025
Your job title makes a bad RBAC role: what access does a Chief Happiness Officer need, anyways? A role in RBAC should represent what someone actually does in your environment. Your job title is your position, not your job function. Read more in our latest blog post: oblique.security/blog/rbac-ro...
oblique.security
Why your RBAC roles aren't actually roles | Oblique
A role in RBAC should represent what someone actually does in your environment. Your job title makes a bad RBAC role: it's your position, not your function.
000
Oblique @oblique.security · 28/08/2025
Comms groups map to how people actually work, and often, access groups don't (but they should). But comms groups always become access groups. It's not a matter of if, but when. Read more in our latest post: oblique.security/blog/comms-a...
oblique.security
Comms groups inevitably become access groups | Oblique
Comms groups map to how people actually work, and often, access groups don't (but they should). Comms groups always become access groups. It's not a matter of if, but when.
000
Oblique @oblique.security · 26/08/2025
Check out our cofounder @mayakaczorowski.com's post on @frankw.bsky.social's Frankly Speaking on how modern security teams are scaling. Read the post for the new commandments of security teams: franklyspeaking.substack.com/p/the-new-co...
franklyspeaking.substack.com
The New Commandments of Security Teams
Guest post by Maya Kaczorowski
031
Oblique @oblique.security · 18/08/2025
Check out the latest from our cofounder @ericchiang.bsky.social to learn about a neat Go type trick to avoid query injection in SQL builders.
010
Oblique @oblique.security · 13/08/2025
Over the past 60 years, we've gone from reusing the same password everywhere to advanced biometric authentication like FaceID. Dive into the history of authentication in just 2 minutes!
020
Oblique @oblique.security · 13/08/2025
Authentication has evolved from simple passwords to federated systems with passwordless logins, with a constant push and pull to balance security and usability. Deep dive into the evolution of authentication in our latest blog post! oblique.security/blog/history...
oblique.security
The evolution of authentication, from passwords to passkeys | Oblique
Authentication has evolved from simple passwords to federated systems with passwordless logins, continuously balancing security and usability.
000
Oblique @oblique.security · 01/08/2025
Instead of minting long-lived API keys, you can use GitHub Actions' OpenID Connect support for workload identity. Here's how we authenticate config-as-code workflows in Oblique without secret management headaches. Better security + Better developer experience 💟 oblique.security/blog/github-...
oblique.security
Authenticating GitHub Actions without API keys | Oblique
Instead of minting long-lived APIs keys and warning users “keep this secret,” let's use GitHub Action's OpenID Connect support instead.
230
Oblique @oblique.security · 28/07/2025
Check out this interview with our co-founder @mayakaczorowski.com on finding and solving problems that have real security impact - like why access management is a perennial issue for organizations. thesecuritywing.com/making-iam-l...
thesecuritywing.com
Making IAM Less Painful: A Security PM's Journey to Founding Oblique Security
TL;DR: I sat down with Maya Kaczorowski who’s building Oblique Security. I chatted about her early beginnings studying math and cryptography to building security products at Google Cloud, GitHub, and ...
020
Oblique @oblique.security · 25/07/2025
Most access request justifications are useless. "Please give me access" doesn't give you any context, it's just someone trying to get back to work. oblique.security/blog/justifi...
oblique.security
Good justifications write themselves | Oblique
Organizations ask users to fill out justification fields when requesting access, but these are useless explanations. Your authorization system should already have the context it needs.
000
Oblique @oblique.security · 28/06/2025
IT teams are afraid of removing access — what if something breaks? Even if you don't know why someone has access, you should be able to figure out if they're using it. Removing unused access isn't risky — never removing access is. Read more in our latest blog post: oblique.security/blog/chester...
oblique.security
Chesterton's fence doesn't apply to access controls | Oblique
IT teams are scared to remove access they don't understand, leading to sprawling entitlements. Removing unused access isn't risky — never removing access is.
000
Oblique @oblique.security · 23/06/2025
Identity management has quietly become the primary security perimeter. But it's a mess — identity requires constant manual work that security teams burn out from. At Oblique, we're helping organizations make their access controls actually maintainable. Full post: oblique.security/blog/identit...
oblique.security
Identity management is harder than it should be | Oblique
Identity management is surprisingly hard, as access controls change constantly, and getting them right requires context. We founded Oblique to work on impactful security problems.
061