Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity vendor compromise: what changes when the signing key is split?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: A single token-signing key can turn an identity vendor compromise into enterprise-wide account takeover, according to Newcore, citing incidents such as the 2023 Microsoft token-signing key theft and Golden SAML. The core issue is that identity platforms still concentrate unilateral signing authority in one place, creating a trust assumption that Zero Trust never removed.

NHIMG editorial — based on content published by Newcore: Secure Split Key (SSK) for identity signing and blast-radius reduction

By the numbers:

Questions worth separating out

Q: How should security teams reduce blast radius in identity-first Zero Trust programmes?

A: They should focus on entitlement scope, not only authentication strength.

Q: Why do identity signing keys create outsized risk for IAM programmes?

A: Because they sit above ordinary user authentication and determine what applications will accept as trusted.

Q: What do security teams get wrong about Zero Trust and identity governance?

A: They often treat Zero Trust as an integration label rather than a continuous operating requirement.

Practitioner guidance

  • Review all signing authorities for single-point compromise risk Inventory every SAML and OIDC trust path that depends on one organisation holding complete signing power.
  • Classify token-signing keys as control-plane secrets Move signing certificates and key material into the same governance tier as privileged infrastructure credentials, with stricter access review, break-glass controls, and monitored ceremony procedures.
  • Map federation trust to explicit blast-radius scenarios Test what an attacker can do if the identity vendor, its support tooling, or its subprocessors are compromised.

What's in the full article

Newcore's full analysis covers the operational detail this post intentionally leaves for the source:

  • Threshold cryptography and split-signing ceremony choices for SAML and OIDC deployments
  • Deployment trade-offs for browser, edge, and device-anchored co-signing paths
  • How the model behaves when a signing share is lost, rotated, or reissued
  • The vendor's scenario matrix comparing legacy identity platforms with split-key signing

👉 Read Newcore's analysis of secure split key for identity signing →

Identity vendor compromise: what changes when the signing key is split?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

Single-key federation is a control-plane concentration problem, not just an authentication problem. When one signing authority can mint access for an entire workforce, the identity layer becomes the fastest path from compromise to enterprise-wide impact. That is not a weakness in MFA or password policy. It is a structural property of unilateral trust. Practitioners should treat the signing key as a governance boundary, not just a cryptographic artefact.

A few things that frame the scale:

  • 64% of valid secrets leaked in 2022 are still valid and exploitable today, proving that detection alone is not enough without automated revocation, according to The State of Secrets Sprawl 2026.
  • 28.65 million new hardcoded secrets were detected in public GitHub commits in 2025 alone, a 34% year-over-year increase and the largest single-year jump ever recorded.

A question worth separating out:

Q: Who is accountable when a signing authority is compromised?

A: Accountability is shared across the vendor operating the signing environment and the customer that accepted unilateral custody of a critical trust function. That is why architecture and contract both matter. The governance question is whether the organisation knowingly allowed one party to hold a skeleton key to its applications.

👉 Read our full editorial: Secure split key changes the trust model for identity vendors



   
ReplyQuote
Share: