<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss-styles.xsl" type="text/xsl"?><rss version="2.0"><channel><title>Uzi Ashkenazi</title><description>Cloud security architect, identity specialist, and builder.</description><link>https://www.uziashkenazi.com/</link><language>en-us</language><item><title>The AWS Security Practitioner&apos;s Guide to Ping Identity</title><link>https://www.uziashkenazi.com/blog/aws-practitioners-guide-to-ping-identity/</link><guid isPermaLink="true">https://www.uziashkenazi.com/blog/aws-practitioners-guide-to-ping-identity/</guid><description>PingOne, PingFederate, PingAccess, PingDirectory, PingAuthorize: five products doing jobs an AWS security practitioner already has names for.</description><pubDate>Sun, 09 Aug 2026 07:00:00 GMT</pubDate><category>ping-identity</category><category>pingfederate</category><category>pingone</category><category>pingauthorize</category><category>aws-iam</category><author>Uzi Ashkenazi</author></item><item><title>Claude Code on the Go</title><link>https://www.uziashkenazi.com/blog/claude-code-on-the-go/</link><guid isPermaLink="true">https://www.uziashkenazi.com/blog/claude-code-on-the-go/</guid><description>Claude Code is a long-running interactive process. Mobile networks are not. The fix is a persistent shell on a VPS, tmux, and Blink Shell on iOS.</description><pubDate>Sun, 17 May 2026 07:00:00 GMT</pubDate><category>claude-code</category><category>tmux</category><category>blink-shell</category><category>mobile-dev</category><category>vps</category><category>workflow</category><author>Uzi Ashkenazi</author></item><item><title>You&apos;ve Been Doing Federation Since Day One</title><link>https://www.uziashkenazi.com/blog/federation-since-day-one/</link><guid isPermaLink="true">https://www.uziashkenazi.com/blog/federation-since-day-one/</guid><description>If you&apos;ve ever assumed an IAM role, you&apos;ve done federation. The protocol primitives you already use in AWS are the same ones that broker identity across vendors.</description><pubDate>Sun, 19 Jul 2026 07:00:00 GMT</pubDate><category>federation</category><category>machine-identity</category><category>oidc</category><category>aws-iam</category><category>aws-sts</category><category>token-exchange</category><category>ping-identity</category><category>nhi</category><author>Uzi Ashkenazi</author></item><item><title>Zero Trust Solved the Human Problem. Machines Are Where the Work Is.</title><link>https://www.uziashkenazi.com/blog/identity-is-the-perimeter/</link><guid isPermaLink="true">https://www.uziashkenazi.com/blog/identity-is-the-perimeter/</guid><description>Zero Trust is sold as a network strategy. That framing buries the lede. The control point moved to the identity layer, and most of those identities aren&apos;t human.</description><pubDate>Sun, 19 Jul 2026 07:00:00 GMT</pubDate><category>zero-trust</category><category>identity-architecture</category><category>nhi</category><category>machine-identity</category><category>fido2</category><category>itdr</category><author>Uzi Ashkenazi</author></item><item><title>Securing the Enterprise on AWS: A Practitioner&apos;s Foundation</title><link>https://www.uziashkenazi.com/blog/securing-the-enterprise-on-aws/</link><guid isPermaLink="true">https://www.uziashkenazi.com/blog/securing-the-enterprise-on-aws/</guid><description>AWS draws a clean line between what it secures and what you secure. Everything on your side of that line turns out to be the same control, wearing four different names.</description><pubDate>Sun, 09 Aug 2026 07:00:00 GMT</pubDate><category>aws-iam</category><category>rbac</category><category>sso</category><category>secrets-management</category><category>itdr</category><category>nhi</category><category>machine-identity</category><author>Uzi Ashkenazi</author></item></channel></rss>