Listen "Authorization vs. Authentication: Decoding the Layers of Security with Emre Baran"
Episode Synopsis
In this episode we dive deep into the world of authorization with Emre Baran, CEO and co-founder of Cerbos. As a seasoned entrepreneur and software expert, Emre brings over 20 years of experience to the table, discussing the subtle yet significant distinctions between authorization and authentication, and why these concepts are pivotal in today's cloud-based and development environments.
In this discussion, Emre explains why many organizations still grapple with these issues in 2024, highlighting common pitfalls in security practices and offering insights into the sophisticated challenges of implementing fine-grained access control. He also shares his views on the evolving landscape of regulatory standards and introduces us to "Cerbos," his solution designed to streamline and secure authorization processes efficiently.
Show Notes
Learn about Corbos: https://www.cerbos.dev/
Cerbos GitHub: https://github.com/cerbos/cerbos
Follow Emre Baran
X / Twitter - https://twitter.com/emre
Linkedin: https://www.linkedin.com/in/emrebaran/
Time Stamps
Intro: 0:00
Why are we still struggling with authz: 1:12
Difference Authentication &Authorization: 6:16
What is Cerbos?: 9:35
The auth trap: 11:58
Is it scalable: 13:20: Scaling Auth
Who owns auth: 16:31
Regulation and compliance: 20:32
GitGuardian: 22:12
What is ZSP (Zero standing Privileges): 23:00
Best and Worst: 28:00
Links and followup: 32:00
In this discussion, Emre explains why many organizations still grapple with these issues in 2024, highlighting common pitfalls in security practices and offering insights into the sophisticated challenges of implementing fine-grained access control. He also shares his views on the evolving landscape of regulatory standards and introduces us to "Cerbos," his solution designed to streamline and secure authorization processes efficiently.
Show Notes
Learn about Corbos: https://www.cerbos.dev/
Cerbos GitHub: https://github.com/cerbos/cerbos
Follow Emre Baran
X / Twitter - https://twitter.com/emre
Linkedin: https://www.linkedin.com/in/emrebaran/
Time Stamps
Intro: 0:00
Why are we still struggling with authz: 1:12
Difference Authentication &Authorization: 6:16
What is Cerbos?: 9:35
The auth trap: 11:58
Is it scalable: 13:20: Scaling Auth
Who owns auth: 16:31
Regulation and compliance: 20:32
GitGuardian: 22:12
What is ZSP (Zero standing Privileges): 23:00
Best and Worst: 28:00
Links and followup: 32:00
More episodes of the podcast The Security Repo
The CISO Whisperer Approach: Security Leadership, Empathy, and ‘Dad Bod’ Metrics – Douglas Brush
17/12/2025
Scaling Open Source Observability and Managing Risk in the Software Supply Chain – Avi Press
10/12/2025
Why Technical CISOs Matter and How AI Is Shaping Security Ops - David Cross on Leading Security
26/11/2025
From Military Intel to CISO: Navigating Security Leadership in the Age of AI – Darren Desmond
12/11/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.