| ▲ | notaharvardmba 6 hours ago | ||||||||||||||||
oauth, saml, oidc accomplish the same thing in a way more mature way, so if you’re already using SSO just do that instead of adding another point of failure.. | |||||||||||||||||
| ▲ | mjg59 6 hours ago | parent [-] | ||||||||||||||||
No they don't - you're still giving the agent a static token that can be exfiltrated and used elsewhere. | |||||||||||||||||
| |||||||||||||||||