Awesome Iam
👤 Identity and Access Management knowledge for cloud platforms
IAMstands for Identity and Access Management. It is a complex domain which covers user accounts, authentication,…
The EnterpriseReady SaaS Feature GuidesThe majority of the features making B2B users happy will be implemented by the IAM perimeter.
IAM is hard. It's really hard.“Overly permissive AWS IAM policies that allowed s3:GetObject to * (all) resources”, led to $80 million fine for…
IAM Is The Real Cloud Lock-InA little click-baity, but author admit that “It depends on how much you trust them to 1. Stay in business; 2. Not jack…
Enterprise Information SecurityMozilla's security and access guidelines.
Mitigating Cloud Vulnerabilities“This document divides cloud vulnerabilities into four classes (misconfiguration, poor access control, shared tenancy…
Cartography🆓 A Neo4J-based tool to map out dependencies and relationships between services and resources. Supports AWS, GCP,…
Open guide to AWS Security and IAMLinks to the Billing and Cost Management section which details the broad characteristics of billing for a cloud…
As a user, I want…A meta-critic of account management, in which features expected by the business clash with real user needs, in the…
Things end users care about but programmers don'tIn the same spirit as above, but broader: all the little things we overlook as developers but users really care about.…
Separate the account, user and login/auth detailsSound advice to lay down the foundation of a future-proof IAM API.
Identity Beyond UsernamesOn the concept of usernames as identifiers, and the complexities introduced when unicode characters meets uniqueness…
Kratos💸 User login, user registration, 2FA and profile management.
UserFrosting🆓 Modern PHP user login and management framework.
Cryptographic Right AnswersAn up to date set of recommendations for developers who are not cryptography engineers. There's even a shorter summary…
Real World Crypto SymposiumAims to bring together cryptography researchers with developers, focusing on uses in real-world environments such as…
An Overview of Cryptography“This paper has two major purposes. The first is to define some of the terms and concepts behind basic cryptographic…
Papers we love: CryptographyFoundational papers of cryptography.
Lifetimes of cryptographic hash functions“If you are using compare-by-hash to generate addresses for data that can be supplied by malicious users, you should…
Security Recommendations for Any Device that Depends on Randomly-Generated Numbers“The phrase 'random number generator' should be parsed as follows: It is a random generator of numbers. It is not a…
RFC #4122: UUID - Security Considerations“Do not assume that UUIDs are hard to guess; they should not be used as security capabilities (identifiers whose mere…
Awesome IdentifiersA benchmark of all identifier formats.
Awesome GUIDFunny take on the global aspect of unique identifiers.
BeyondCorp: A New Approach to Enterprise SecurityQuick overview of Google's Zero-trust Network initiative.
What is BeyondCorp? What is Identity-Aware Proxy?More companies add extra layers of VPNs, firewalls, restrictions and constraints, resulting in a terrible experience…
oathkeeper💸 Identity & Access Proxy and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP…
Pomerium💸 An identity-aware proxy that enables secure access to internal applications.
heimdall🆓 A cloud-native, identity-aware proxy and policy enforcement point that orchestrates authentication and…
SPIFFE/SPIRE🆓 A CNCF framework issuing short-lived, cryptographically-verifiable identities (SVIDs) to workloads across…
NanoMDM🆓 Minimalist Apple MDM server and library to enroll and manage the identity of Apple devices, inspired by MicroMDM.
API Tokens: A Tedious SurveyAn overview and comparison of all token-based authentication schemes for end-user APIs.
A Child's Garden of Inter-Service Authentication SchemesIn the same spirit as above, but this time at the service level.
Scaling backend authentication at FacebookHow-to in a nutshell: 1. Small root of trust; 2. TLS isn't enough; 3. Certificate-based tokens; 4. Crypto Auth Tokens…
The new NIST password guidanceA summary of NIST Special Publication 800-63B covering new password complexity guidelines.
Password Storage Cheat SheetThe only way to slow down offline attacks is by carefully choosing hash algorithms that are as resource intensive as…
Password expiration is deadRecent scientific research calls into question the value of many long-standing password-security practices such as…
Practical Recommendations for Stronger, More Usable PasswordsThis study recommend the association of: blocklist checks against commonly leaked passwords, password policies without…
Banks, Arbitrary Password Restrictions and Why They Don't Matter“Arbitrary low limits on length and character composition are bad. They look bad, they lead to negative speculation…
Dumb Password Rules🆓 Shaming sites with dumb password rules.
Password Manager Resources🆓 A collection of password rules, change URLs and quirks by sites.
A Well-Known URL for Changing Passwords🆓 Specification defining site resource for password updates.
How to change the hashing scheme of already hashed user's passwordsGood news: you're not stuck with a legacy password saving scheme. Here is a trick to transparently upgrade to stronger…
Breaking Password Dependencies: Challenges in the Final Mile at MicrosoftThe primary source of account hacks is password spraying (on legacy auth like SMTP, IMAP, POP, etc.), second is replay…
Beyond Passwords: 2FA, U2F and Google Advanced ProtectionAn excellent walk-trough over all these technologies.
A Comparative Long-Term Study of Fallback AuthenticationKey take-away: “schemes based on email and SMS are more usable. Mechanisms based on designated trustees and personal…
Secrets, Lies, and Account Recovery: Lessons from the Use of Personal Knowledge Questions at Google“Our analysis confirms that secret questions generally offer a security level that is far lower than user-chosen…
How effective is basic account hygiene at preventing hijackingGoogle security team's data shows 2FA blocks 100% of automated bot hacks.
Your Pa$$word doesn't matterSame conclusion as above from Microsoft: “Based on our studies, your account is more than 99.9% less likely to be…
Attacking Google AuthenticatorProbably on the verge of paranoia, but might be a reason to rate limit 2FA validation attempts.
Compromising online accounts by cracking voicemail systemsOr why you should not rely on automated phone calls as a method to reach the user and reset passwords, 2FA or for any…
Getting 2FA Right in 2019On the UX aspects of 2FA.
2FA is missing a key feature“When my 2FA code is entered incorrectly I'd like to know about it”.
SMS Multifactor Authentication in AntarcticaDoesn't work because there are no cellphone towers at stations in Antarctica.
Authelia🆓 Open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO)…
Kanidm🆓 Simple, secure and fast identity management platform.
SMS 2FA auth is deprecated by NISTNIST has said that 2FA via SMS is bad and awful since 2016.
SMS: The most popular and least secure 2FA methodIs SMS 2FA Secure? No.Definitive research project demonstrating successful attempts at SIM swapping.
Hackers Hit Twitter C.E.O. Jack Dorsey in a 'SIM Swap.' You're at Risk, Too.AT&T rep handed control of his cellphone account to a hackerAn argument for passwordlessPasswords are not the be-all and end-all of user authentication. This article tries to tell you why.
Magic Links – Are they Actually Outdated?What are magic links, their origin, pros and cons.
WebAuthn guideIntroduce WebAuthn as a standard supported by all major browsers, and allowing “servers to register and authenticate…
Clearing up some misconceptions about PasskeysOr why passkeys are not worse than passwords.
Webauthn and security keysDescribe how authentication works with security keys, details the protocols, and how they articulates with WebAuthn.…
Getting started with security keysA practical guide to stay safe online and prevent phishing with FIDO2, WebAuthn and security keys.
OpenSK🆓 Open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
YubiKey GuideGuide to using YubiKey as a SmartCard for storing GPG encryption, signing and authentication keys, which can also be…
PKI for busy peopleQuick overview of the important stuff.
Everything you should know about certificates and PKI but are too afraid to askPKI lets you define a system cryptographically. It's universal and vendor neutral.
lemur🆓 Acts as a broker between CAs and environments, providing a central portal for developers to issue TLS certificates…
CFSSL🆓 A swiss army knife for PKI/TLS by CloudFlare. Command line tool and an HTTP API server for signing, verifying, and…
JA4+💸 A suite of network fingerprinting methods to facilitate threat-hunting and analysis.
JSON Web Tokenis a bearer's token.
Introduction to JSON Web TokensGet up to speed on JWT with this article.
Learn how to use JWT for AuthenticationLearn how to use JWT to secure your web app.
Using JSON Web Tokens as API KeysCompared to API keys, JWTs offers granular security, homogeneous auth architecture, decentralized issuance, OAuth2…
Hardcoded secrets, unverified tokens, and other common JWT mistakesA good recap of all JWT pitfalls.
Adding JSON Web Token API Keys to a DenyListOn token invalidation.
Stop using JWT for sessionsAnd why your "solution" doesn't work, because stateless JWT tokens cannot be invalidated or updated. They will…
JWT, JWS and JWE for Not So Dummies!A signed JWT is known as a JWS (JSON Web Signature). In fact a JWT does not exist itself — either it has to be a JWS…
JOSE is a Bad Standard That Everyone Should AvoidThe standards are either completely broken or complex minefields hard to navigate.
JWT.ioAllows you to decode, verify and generate JWT.
Why Authorization is HardBecause it needs multiple tradeoffs on Enforcement which is required in so many places, on Decision architecture to…
The never-ending product requirements of user authorizationHow a simple authorization model based on roles is not enough and gets complicated fast due to product packaging, data…
RBAC like it was meant to beHow we got from DAC (unix permissions, secret URL), to MAC (DRM, MFA, 2FA, SELinux), to RBAC. Details how the latter…
The Case for Granular PermissionsDiscuss the limitations of RBAC and how ABAC (Attribute-Based Access Control) addresses them.
In Search For a Perfect Access Control SystemThe historical origins of authorization schemes. Hints at the future of sharing, trust and delegation between…
GCP's IAM syntax is better than AWS'sThe minutiae of permission design in GCP improves the developer's experience.
Semantic-based Automated Reasoning for AWS Access Policies using SMTZelkova is how AWS does it. This system perform symbolic analysis of IAM policies, and solve the reachability of…
Authorization AcademyAn in-depth, vendor-agnostic treatment of authorization that emphasizes mental models. This guide shows the reader how…
Role-Based Access Controlis the classical model to map users to permissions by the way of roles.
Athenz🆓 Set of services and libraries supporting service authentication and role-based authorization for provisioning and…
BiscuitMerges concepts from cookies, JWTs, macaroons and Open Policy Agent. “It provide a logic language based on Datalog to…
Cerbos💸 An authorization endpoint to write context-aware access control policies.
FerrisKey🆓 Self-hosted, open-source, RBAC system written in Rust.
Attribute-Based Access Controlis an evolution of RBAC, in which roles are replaced by attributes, allowing the implementation of more complex…
Keto💸 Policy decision point. It uses a set of access control policies, similar to AWS policies, in order to determine…
Ladon💸 Access control library, inspired by AWS.
Casbin🆓 Open-source access control library for Golang projects.
Open Policy Agent🆓 An open-source general-purpose decision engine to create and enforce ABAC policies.
Zanzibar: Google's Consistent, Global Authorization SystemScales to trillions of access control lists and millions of authorization requests per second to support services used…
SpiceDB💸 An open source database system for managing security-critical application permissions inspired by Zanzibar.
Permify💸 Another open-source authorization as a service inspired by Google Zanzibar, and see how it compares to other…
Topaz💸 An open-source project which combines the policy-as-code and decision logging of OPA with a Zanzibar-modeled…
Open Policy Administration Layer💸 Open Source administration layer for OPA, detecting changes to both policy and policy data in realtime and pushing…
An AWS IAM Security Tooling ReferenceA comprehensive list of (maintained) tools for AWS IAM.
Become an AWS IAM Policy Ninja“In my nearly 5 years at Amazon, I carve out a little time each day, each week to look through the forums, customer…
AWS IAM Roles, a tale of unnecessary complexityThe history of fast-growing AWS explains how the current scheme came to be, and how it compares to GCP's resource…
Policy Sentry🆓 Writing security-conscious IAM Policies by hand can be very tedious and inefficient. Policy Sentry helps users to…
IAM Floyd🆓 AWS IAM policy statement generator with fluent interface. Helps with creating type safe IAM policies and writing…
IAMbic💸 GitOps for IAM. The Terraform of Cloud IAM. IAMbic is a multi-cloud identity and access management (IAM) control…
Google's Macaroons in Five Minutes or LessIf I'm given a Macaroon that authorizes me to perform some action(s) under certain restrictions, I can…
Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the CloudGoogle's original paper.
Google paper's author compares Macaroons and JWTsAs a consumer/verifier of macaroons, they allow you (through third-party caveats) to defer some authorization…
Gubernator🆓 High performance rate-limiting micro-service and library.
OAuth 2.0is a delegated authorization framework. OpenID Connect (OIDC) is an authentication layer on top of it.
DescopeDrag and drop your auth. Add authentication, user management, and authorization to your app with a few lines of code.
Awesome OpenID ConnectA curated list of providers, services, libraries, and resources for OpenID Connect.
An Illustrated Guide to OAuth and OpenID ConnectExplain how these standards work using simplified illustrations.
OAuth 2 SimplifiedA reference article describing the protocol in simplified format to help developers and service providers implement it.
OAuth 2.0 and OpenID Connect (in plain English)Starts with an historical context on how these standards came to be, clears up the inaccuracies in the vocabulary,…
OAuth in one pictureA nice summary card.
How to Implement a Secure Central Authentication Service in Six StepsGot multiple legacy systems to merge with their own login methods and accounts? Here is how to merge all that mess by…
Open-Sourcing BuzzFeed's SSO ExperienceOAuth2-friendly adaptation of the Central Authentication Service (CAS) protocol. You'll find there good OAuth user…
OAuth 2.0 Security Best Current Practice“Updates and extends the OAuth 2.0 Security Threat Model to incorporate practical experiences gathered since OAuth 2.0…
Hidden OAuth attack vectorsHow to identify and exploit some of the key vulnerabilities found in OAuth 2.0 authentication mechanisms.
PKCE Explained“PKCE is used to provide one more security layer to the authorization code flow in OAuth and OpenID Connect.”
Hydra💸 Open-source OIDC & OAuth2 Server Provider.
Keycloak🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password…
Casdoor🆓 A UI-first centralized authentication / Single-Sign-On (SSO) platform. Supports OAuth 2, OIDC, SAML 2, CAS, LDAP…
authentik💸 Open-source Identity Provider similar to Keycloak.
ZITADEL💸 An Open-Source solution built with Go and Angular to manage all your systems, users and service accounts together…
obligator🆓 Simple and opinionated OpenID Connect server designed for self-hosters. Single static binary with flat-file or…
SAML vs. OAuth“OAuth is a protocol for authorization: it ensures Bob goes to the right parking lot. In contrast, SAML is a protocol…
The Difference Between SAML 2.0 and OAuth 2.0“Even though SAML was actually designed to be widely applicable, its contemporary usage is typically shifted towards…
What's the Difference Between OAuth, OpenID Connect, and SAML?Identity is hard. Another take on the different protocol is always welcome to help makes sense of it all.
The Beer Drinker's Guide to SAMLSAML is arcane at times. A another analogy might helps get more sense out of it.
SAML: A Fractal of Bad Design“SAML is being crushed under the weight of its own complexity.” The author lists five flaws that compound: “1. Built…
SAML is insecure by designNot only weird, SAML is also insecure by design, as it relies on signatures based on XML canonicalization, not XML…
The Difficulties of SAML Single LogoutOn the technical and UX issues of single logout implementations.
The SSO Wall of ShameA documented rant on the excessive pricing practiced by SaaS providers to activate SSO on their product. The author's…
Secret at Scale at NetflixSolution based on blind signatures. See the slides.
High Availability in Google's Internal KMSNot GCP's KMS, but the one at the core of their infrastructure. See the slides.
HashiCorp Vault💸 Secure, store and tightly control access to tokens, passwords, certificates, encryption keys.
Infisical💸 An alternative to HashiCorp Vault.
sops🆓 Editor of encrypted files that supports YAML, JSON, ENV, INI and BINARY formats and encrypts with AWS KMS, GCP KMS,…
gitleaks🆓 Audit Git repos for secrets.
trufflehog💸 Searches through Git repositories for high entropy strings and secrets, digging deep into commit history.
HSM: What they are and why it's likely that you've (indirectly) used one todayReally basic overview of HSM usages.
Tidbits on AWS Cloud HSM hardwareAWS CloudHSM Classic is backed by SafeNet's Luna HSM, current CloudHSM rely on Cavium's Nitrox, which allows for…
Keystone🆓 Open-source project for building trusted execution environments (TEE) with secure hardware enclaves, based on the…
Project Oak🆓 A specification and a reference implementation for the secure transfer, storage and processing of data.
Everybody be cool, this is a robbery!A case study of vulnerability and exploitability of a HSM (in French, sorry).
Trust and safety 101A great introduction on the domain and its responsibilities.
What the Heck is Trust and Safety?A couple of real use-case to demonstrate the role of a TnS team.
Awesome List of Billing and Payments: Fraud linksSection dedicated to fraud management for billing and payment, from our sister repository.
The Laws of IdentityIs this paper aims at identity metasystem, its laws still provides great insights at smaller scale, especially the…
How Uber Got Lost“To limit "friction" Uber allowed riders to sign up without requiring them to provide identity beyond an email —…
A Comparison of Personal Name Matching: Techniques and Practical IssuesCustomer name matching has lots of application, from account deduplication to fraud monitoring.
Statistically Likely Usernames🆓 Wordlists for creating statistically likely usernames for use in username-enumeration, simulated password-attacks…
Facebook Dangerous Individuals and Organizations ListSome groups and content are illegal in some juridictions. This is an example of a blocklist.
Ballerine💸 An open-source infrastructure for user identity and risk management.
Sherlock🆓 Hunt down social media accounts by username across social networks.
After Car2Go eased its background checks, 75 of its vehicles were stolen in one day.Why background check are sometimes necessary.
Investigation into the Unusual SignupsA really detailed analysis of suspicious contributor signups on OpenStreetMap. This beautiful and high-level report…
MIDAS: Detecting Microcluster Anomalies in Edge Streams🆓 A proposed method to “detects microcluster anomalies, or suddenly arriving groups of suspiciously similar edges, in…
Gephi🆓 Open-source platform for visualizing and manipulating large graphs.
Still Logged In: What AR and VR Can Learn from MMOs“If you host an online community, where people can harm another person: you are on the hook. And if you can't afford…
You either die an MVP or live long enough to build content moderation“You can think about the solution space for this problem by considering three dimensions: cost, accuracy and speed.…
The despair and darkness of people will get to youModeration of huge social networks is performed by an army of outsourced subcontractors. These people are exposed to…
The CleanersA documentary on these teams of underpaid people removing posts and deleting accounts.
Awesome Threat Intelligence“A concise definition of Threat Intelligence: evidence-based knowledge, including context, mechanisms, indicators,…
SpiderFoot🆓 An open source intelligence (OSINT) automation tool. It integrates with just about every data source available and…
OSINT Stuff Tool Collection“A collection of several hundred online tools for OSINT”: domain, IP, email, username and social-network lookups…
Maigret🆓 “Collect a dossier on a person by username from 3000+ sites”, useful for account enumeration and unmasking fraud or…
Standards related to Threat IntelligenceOpen standards, tools and methodologies to support threat intelligence analysis.
MISP taxonomies and classificationTags to organize information on “threat intelligence including cyber security indicators, financial fraud or…
Browser Fingerprinting: A surveyFingerprints can be used as a source of signals to identify bots and fraudsters.
The challenges of file formatsAt one point you will let users upload files in your system. Here is a corpus of suspicious media files that can be…
SecLists🆓 Collection of multiple types of lists used during security assessments, collected in one place. List types include…
PhishingKitTracker🆓 CSV database of email addresses used by threat actor in phishing kits.
PhoneInfoga🆓 Tools to scan phone numbers using only free resources. The goal is to first gather standard information such as…
Confusable Homoglyphs🆓 Homoglyphs is a common phishing trick.
Awesome CaptchaReference all open-source captcha libraries, integration, alternatives and cracking tools.
reCaptcha💸 Still an effective, economical and quick solution when your company can't afford to have a dedicated team to fight…
You (probably) don't need ReCAPTCHAStarts with a rant on how the service is a privacy nightmare and is tedious UI-wise, then list alternatives.
Anubis🆓 An open-source solution to protect upstream resources from scraper bots.
Anti-captcha💸 Captchas solving service.
Bloom FilterPerfect for this use-case, as bloom filters are designed to quickly check if an element is not in a (large) set.…
How Radix trees made blocking IPs 5000 times fasterRadix trees might come handy to speed-up IP blocklists.
hosts🆓 Consolidates reputable hosts files, and merges them into a unified hosts file with duplicates removed.
nextdns/metadata💸 Extensive collection of list for security, privacy and parental control.
The Public Suffix List🆓 Mozilla's registry of public suffixes, under which Internet users can (or historically could) directly register…
Country IP Blocks🆓 CIDR country-level IP data, straight from the Regional Internet Registries, updated hourly.
common-domain-prefix-suffix-list.tsvTop-5000 most common domain prefix/suffix list.
xkeyscorerules100.txtNSA's XKeyscore matching rules for TOR and other anonymity preserving tools.
AMF site blocklistOfficial French denylist of money-related fraud sites.
Burner email providers🆓 A list of temporary email providers. And its derivative Python module.
MailChecker💸 Cross-language temporary (disposable/throwaway) email detection library.
check-if-email-exists💸 Verify an email address's reachability over SMTP without sending anything, catching typos, disposable domains and…
Temporary Email Address DomainsA list of domains for disposable and temporary email addresses. Useful for filtering your email list to increase open…
gman🆓 “A Ruby gem to check if the owner of a given email address or website is working for THE MAN (a.k.a verifies…
General List of Reserved WordsThis is a general list of words you may want to consider reserving, in a system where users can pick any name.
Hostnames and usernames to reserveList of all the names that should be restricted from registration in automated systems.
List of Dirty, Naughty, Obscene, and Otherwise Bad Words🆓 Profanity blocklist from Shutterstock.
profanity-check🆓 Uses a linear SVM model trained on 200k human-labeled samples of clean and profane text strings.
Papers we love: CryptographyFoundational papers of cryptography.
Have I been Pwned?Data breach index.
Automated security testing for Software DevelopersMost privacy breaches were allowed by known vulnerabilities in third-party dependencies. Here is how to detect them by…
Email marketing regulations around the world🆓 As the world becomes increasingly connected, the email marketing regulation landscape becomes more and more complex.
The False Allure of Hashing for AnonymizationHashing is not sufficient for anonymization no. But still it is good enough for pseudonymization (which is allowed by…
Four cents to deanonymize: Companies reverse hashed email addresses“Hashed email addresses can be easily reversed and linked to an individual”.
Why differential privacy is awesomeExplain the intuition behind differential privacy, a theoretical framework which allow sharing of aggregated data…
Presidio🆓 Context aware, pluggable and customizable data protection and PII data anonymization service for text and images.
GDPR TrackerEurope's reference site.
GDPR Developer GuideBest practices for developers.
GDPR – A Practical guide for DevelopersA one-page summary of the above.
Dark Patterns after the GDPRThis paper demonstrates that, because of the lack of GDPR law enforcements, dark patterns and implied consent are…
GDPR Enforcement TrackerList of GDPR fines and penalties.
The 2020 State of SaaS Product OnboardingCovers all the important facets of user onboarding.
User Onboarding TeardownsA huge list of deconstructed first-time user signups.
Discover UI Design Decisions Of Leading CompaniesFrom Leaked Screenshots & A/B Tests.
Conversion OptimizationA collection of tactics to increase the chance of users finishing the account creation funnel.
11 Tips for Better Signup / Login UXSome basic tips on the login form.
Don't get clever with login formsCreate login forms that are simple, linkable, predictable, and play nicely with password managers.
Why are the username and password on two different pages?To support both SSO and password-based login. Now if breaking the login funnel in 2 steps is too infuriating to users,…
HTML attributes to improve your users' two factor authentication experience“In this post we will look at the humble <input> element and the HTML attributes that will help speed up our users'…
Remove password maskingSummarizes the results from an academic study investigating the impact removing password masking has on consumer trust.
For anybody who thinks "I could build that in a weekend," this is how Slack decides to send a notificationNotifications are hard. Really hard.
Best-of Digital IdentityRanking, popularity and activity status of open-source digital identity projects.
AWS Security, Identity & Compliance announcementsThe source of all new features added to the IAM perimeter.
GCP IAM release notesAlso of note: Identity Platform, Resource Manager, Key Management Service/HSM, Access Context Manager, Identity-Aware…
Unofficial Weekly Google Cloud Platform newsletterRelevant keywords: IAM and Security.
DigitalOcean Accounts changelogAll the latest accounts updates on DO.
163 AWS services explained in one line eachHelp makes sense of their huge service catalog. In the same spirit: AWS In Plain English.
Google Cloud Developer's Cheat SheetDescribe all GCP products in 4 words or less.
cryptoanarchy.wikiCypherpunks overlaps with security. This wiki compiles information about the movement, its history and the…