Security at Scale — Middle¶
Use STRIDE to examine spoofing, tampering, repudiation, disclosure, denial, and privilege escalation. OAuth 2 delegates authorization; OIDC adds identity; JWT is a token format, not an access-control design.
Use KMS envelope encryption, automated certificate rotation, rate limits, WAF controls, and scoped service identities. Test key expiry, revocation, clock skew, and dependency compromise.
Test yourself¶
- Which trust boundary needs a threat model?
- Why is JWT validation insufficient for authorization?
- How does envelope encryption work?
- Which abuse limit protects expensive work?
Continue to senior.md.