Loading…
BSidesSF 2018 has ended
Back To Schedule
Monday, April 16 • 11:40am - 12:10pm
Managing secrets in your cloud environment: AWS, GCP, and containers (and beyond)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Applications often require access to sensitive data at build or run time, known as secrets. As a cloud application developer, you have many options to store these secrets, such as in code, environment variables, or purpose built solutions. We’ll discuss what a secret is, how secrets are stored today and some common mistakes in secret management, identity as it relates to accessing secrets, criteria to evaluate a secret management solution, and common solutions for containers in AWS, GCP, and Azure, and lastly, unsolved security risks.

Users should walk away from the talk as experts on secrets management in the cloud. How to improve their secret management practices, and understand their current security and usability tradeoffs.

Presenters
avatar for Evan Johnson

Evan Johnson

Senior Security Engineer, Cloudflare
Evan Johnson is a member of the Product Security team at Cloudflare. He loves diet pepsi, chicken nuggets, and golang. No relation to the prolific Linkedin content producer, Mike Johnson.
avatar for Maya Kaczorowski

Maya Kaczorowski

Product Manager, Software Supply Chain Security, GitHub
Maya is a Product Manager for Software Supply Chain Security at GitHub. She was previously at Google, focused on container security, and encryption at rest and encryption key management. Prior to Google, she was at McKinsey & Company, and before that, completed her Master's in mathematics... Read More →



Monday April 16, 2018 11:40am - 12:10pm PDT
AMC - Theatre 7