Securing Remote MCP Servers

No ratings

Presented at fwd:cloudsec North America 2025 by

Once again what's old is new. Its looking like MCP is gonna be here for awhile so its only a matter of time before an enabled developer asks for sign off on something that works great on their local. This lightning talk is geared to provide cloud security professionals with an up to date understanding of best (or least bad) practices. We’ll cover: - Layers of uncertainty: With a spec in active development and not even a transport layer fully agreed upon, how do you approach deploying something before the recommended architectures are even decided on? - Trends: What are other folks doing? Is OAuth actually feasible? What else has been done? How are people working around limitations and what are the risks? What is SSE, why is it deprecated but still implemented everywhere and what do I do when they tell me it "needs websockets"? - Documented paths forward: What is the community doing? What standards have been released to help align? What tools and frameworks exist to make our jobs easier? - What could go wrong? A dive into cloud specific threat vectors, covering the theoretical and maybe even real world incidents