OAuth Works for AI Agents but Scaling is Another Question
Maya Kaczorowski noticed that AI identity and AI agent identity concerns were emerging from outside the security industry, rather than from CISOs and security leaders. She concluded that OAuth, the open standard for authentication, already serves the purpose of granting access without exposing passwords.
Kaczorowski, a respected technologist and founder of Oblique, a startup focused on self-serve access controls, recently wrote about OAuth and AI agents and shared her insights on this episode of The New Stack Makers. She noted that developers see AI agents as extensions of themselves, granting them limited access to data and capabilities—precisely what OAuth is designed to handle.
The challenges with AI agent identity are vast, involving different approaches to authentication, such as those explored by companies like AuthZed. While existing authorization models like RBAC or ABAC may still apply, the real challenge lies in scale. The exponential growth of AI-related entities—from users to LLMs—could mean even small organizations manage hundreds of thousands of agents. Future solutions must accommodate this massive scale efficiently.
For the full discussion, check out The New Stack Makers interview with Kaczorowski.
Learn more from The New Stack about OAuth requirements for AI Agents:
OAuth 2.0: A Standard in Name Only?
AI Agents Are Redefining the Future of Identity and Access Management
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
How Tailscale Builds for Users of All Tiers with Maya Kaczorowski
Maya Kaczorowski, Chief Product Officer at Tailscale, joins Corey on Screaming in the Cloud to discuss what sets the Tailscale product approach apart, for users of their free tier all the way to enterprise. Maya shares insight on how she evaluates feature requests, and how Tailscale’s unique architecture sets them apart from competitors. Maya and Corey discuss the importance of transparency when building trust in security, as well as Tailscale’s approach to new feature roll-outs and change management.
About Maya
Maya is the Chief Product Officer at Tailscale, providing secure networking for the long tail. She was mostly recently at GitHub in software supply chain security, and previously at Google working on container security, encryption at rest and encryption key management. Prior to Google, she was an Engagement Manager at McKinsey & Company, working in IT security for large enterprises.
Maya completed her Master's in mathematics focusing on cryptography and game theory. She is bilingual in English and French.
Outside of work, Maya is passionate about ice cream, puzzling, running, and reading nonfiction.
Links Referenced:
Tailscale: https://tailscale.com/
Tailscale features:VS Code extension: https://marketplace.visualstudio.com/items?itemName=tailscale.vscode-tailscale
Tailscale SSH: https://tailscale.com/kb/1193/tailscale-ssh
Tailnet lock: https://tailscale.com/kb/1226/tailnet-lock
Auto updates: https://tailscale.com/kb/1067/update#auto-updates
ACL tests: https://tailscale.com/kb/1018/acls#tests
Kubernetes operator: https://tailscale.com/kb/1236/kubernetes-operator
Log streaming: https://tailscale.com/kb/1255/log-streaming
Tailscale Security Bulletins: https://tailscale.com/security-bulletins
Blog post “How Our Free Plan Stays Free:” https://tailscale.com/blog/free-plan
Tailscale on AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-nd5zazsgvu6e6
Security, with Maya Kaczorowski
On this week's Kubernetes Podcast, your hosts talk to Maya Kaczorowski from Google Cloud about Kubernetes security, and look at announcements from Microsoft, Docker, Cisco and Spotify.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
News of the week Microsoft Azure Kubernetes Service goes GA
IBM launch multi-zone clusters
Dockercon: Federated application management
Extending Kubernetes to Windows Server with Docker Enterprise Edition
Design applications in Docker Desktop
Cisco Live announcement on CCP, Kuberenetes, and Cloud partnership
How Spotify is migrating from an in-house Docker orchestration platform to Kubernetes
Links from the interview Kromtech article on cryptojacking
Security scanning tools: Clair
MicroScanner
Kubernetes secrets Use an KMS provider for data protection
Hashicorp Vault and Kubernetes
Cluster hardening guides: GKE Security Overview
GKE cluster hardening
Kubernetes.io docs on cluster security
Exploring Container Security blog series Overview by Maya Kaczorowski
Node and container operating systemes by Aditya Kal and Dan Lorenc
Digging into Grafeas container image metadata by Felix Glaser and Wendy Dembowski
Protecting and defending your Kubernetes Engine network, by Manjot Pahwa, Ahmet Alp Balkan and Bowei Du
Running a tight ship with Kubernetes Engine 1.10 by Aaron Small and Vic Iglesias
Using Cloud Security Command Center (and five partner tools) to detect and manage an attack by Maya Kaczorowski and Andy Chang
Isolation at different layers of the Kubernetes stack by Tim Allclair and Maya Kaczorowski
@MayaKaczorowski on Twitter