End-to-end tests considered harmful (securing credentials for E2E and synthetic testing)
by Katie Kodes | at Minnebar20 | 11:35 β 12:15 in Louis Pasteur | View Schedule
Last summer, eager to show a team how easily they could author Microsoft Playwright tests to determine whether their site still works after each new vendor patch ... I came five seconds away from hitting "send" on a test run results report that would have included:
- screenshots of my bank account number, and
- browser history including a cookie that could have let them log in as me and reroute my next payments to themselves.
My impatient boundless enthusiasm is partly to blame, but it could happen to any of us, because the problem is inherent to the nature of automation:
- Credential problems arise quickly when we take humans out of the loop and automate testing authenticated systems.
This session explores the security implications of common testing practices, and presents practical alternatives that maintain quality assurance and observability without compromising security.
You'll learn authentication and authorization patterns to improve test security across the software development lifecycle.
Properly implementing mitigations like health check endpoints, synthetic data, and privilege separation likely involves more subject matter expertise than is reasonable to expect everyone to hold at once, so you'll leave this session with a shareable vocabulary you can use to align business, development, quality, identity, security, and monitoring teams as you work toward safer test automation against your most important systems.
Katie Kodes
Once told, "I've always imagined your brain is shaped like an old-fashioned library card catalog," Katie is thrilled by any chance to help others find -- and maintain -- order in their data and tech processes.
Links:
Are you interested in this session?
This will add your name to the list of interested participants. It will help us gauge interest for scheduling purposes.
Interested Participants
Similar Sessions
Does this session sound interesting? You may also like these:
-
What the fuck are passkeys and why are they everywhere now?
by Dan Lew -
The Parts You Didn't See: A Collective Account of Operation Metro Surge
by Eryn O'Neil -
What tech lessons should we learn from the ICE invasion?
-
π‘πΈοΈ Preppers & Comrades Unite: Building a Decentralized Mesh Network for Resilient Communication
-
No One Has the Full Picture (Especially in Complex Systems)
by Tom Harren