Recent years saw a surge in cloud tech adoption, highlighting the efficiency through tools like Google’s Domain-Wide Delegation.
It enables GCP (Google Cloud Platform) identities to perform tasks in GWS (Google Workspace) apps on behalf of Workspace users, streamlining work processes.
Cybersecurity researchers at Hunters’ Team Axon recently found a design flaw in Google Workspace’s Domain-Wide Delegation, which is dubbed as “DeleFriend.”
This flaw allows:-
StorageGuard scans, detects, and fixes security misconfigurations and vulnerabilities across hundreds of storage and backup devices.
Google Cloud and Workspace share a vital connection through Domain-Wide Delegation. While Google Cloud IAM handles internal resource control, Workspace is the central ‘hub’ for user management.
The integrated identity concept is key, whether through Workspace or Cloud Identity, even for organizations using third-party IdP like Okta or Azure AD for GCP services.
Google Workspace’s Domain-Wide Delegation streamlines app access to Workspace data and helps boost efficiency.
With OAuth 2.0, developers grant service accounts user data access without individual consent, which:-
Here below, we have mentioned the types of main global delegated object identities that Google Workspace allows to create:-
Google adopts OAuth 2.0 RFC 6749 for delegated authorization, mirroring other cloud providers. This allows identities to grant permissions to Workspace REST API apps without exposing credentials.
However, besides this, the researchers demonstrated the flaw with the help of two scenarios, and here below, we have mentioned those scenarios:-
Here below, we have mentioned all the advantages that this attack vector brings to the threat actors:-
Here below we have mentioned all the mitigation recommendations that the cybersecurity researchers recommend:-
Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.
Google has once again raised the bar for mobile security by introducing two new AI-powered…
Daren Li, 41, a dual citizen of China and St. Kitts and Nevis, and a…
Google Cloud has announced a significant step forward in its commitment to transparency and security…
GitLab has rolled out critical security updates to address multiple vulnerabilities in its Community Edition…
A newly discovered zero-day vulnerability, CVE-2024-43451, has been actively exploited in the wild, targeting Windows systems…
Keeping track of who has access and managing their permissions has gotten a lot more…