Enforcing Device AuthN & Compliance at Pinterest | by Pinterest Engineering | Pinterest Engineering Blog | Medium
Pinterest has enforced the use of managed and compliant devices in our Okta authentication flow, using a passwordless implementation, so that access to our tools always requires a healthy Pinterest device. Following the phishing-based attacks against our peers in the tech industry, Pinterest decided to take a two pronged approach to defend against similar attacks. We decided to: In this post, we’ll be focusing on how we required the use of Pinterest managed devices in our Okta authentication flow. There are a few driving forces behind this initiative: We feel that requiring a managed and healthy device for authentication mitigates some of the lost security boundaries described above, by ensuring that: While researching the different integration options within Okta, a few things became apparent for Okta Classic customers: Therefore, we didn’t have much of a choice but to build and route users to our own custom identity provider. Zuul (apologies Netflix) is an OIDC identity provider that
Pinterest has enforced the use of managed and compliant devices in our Okta authentication flow, using a passwordless implementation, so that access to our tools always requires a healthy Pinterest device. Following the phishing-based attacks against our peers in the tech industry, Pinterest decided to take a two pronged approach to defend against similar attacks. We decided to: In this post, we’ll be focusing on how we required the use of Pinterest managed devices in our Okta authentication flow. There are a few driving forces behind this initiative: We feel that requiring a managed and healt
Explore this link on the map →