Defeating Secrets Sprawl: The Power of Vaultless Secrets Management - Oded Hareven, Akeyless Security
Techstrong TV Interviews
•
01-Jan-1900
The move to the cloud, the dominance of containerization in development and new DevOps methodology have led to a rise in machines – including processes, scripts, applications and containers and databases, among others. These machines require authentication and authorization continuously via secrets (credentials, certificates and keys) and must be continuously accessible. These secrets have consequently been embedded in vulnerable code, scripts, configuration files and CI/CD tools – which is generally called “secrets sprawl.” This sprawl has led to a rise of increasingly prominent hacks and leaks. While secrets vaults were introduced to solve this problem, these vaults are unwieldy, and their complexity can further contribute to sprawl. A remedy is vaultless secrets management: SaaS-based, deployment-free, efficient and scalable. Akeyless' Vaultless™ approach and DFC™ technology offers this solution, tailored to modern development. Oded explains the role of vaultless secrets management within a multi-layered security approach against emerging digital threats.
Up Next in Techstrong TV Interviews
-
The Pitfalls of AI Code Generation - ...
Amy Baker, security education evangelist for Security Journey, explains why relying on generative artificial intelligence (AI) to write code is likely to result in more vulnerabilities than ever finding their way into production environments.
-
Open Source Software Security: Curren...
Henrik Plate, security researcher with Endor Labs, speaks about the direction of open source software (OSS) security, the top open source risks facing organizations today and where most fall short in assessing OSS vulnerabilities, and what we can expect for the future of OSS and supply chain secu...
-
Unlocking the Power of Jenkins CI/CD ...
Shawn Ahmed, chief product officer for CloudBees, dives into the benefits of the first major update to the Jenkins continuous integration/continuous delivery (CI/CD) platform. In addition, he explains where a completely different DevSecOps platform, built using Tekton pipelines, fits in the DevOp...