Loading…
Attending this event?
Thursday, June 27 • 11:30am - 12:15pm
From Zero to Hero: Rollout your hardcoded secrets detection and prevention with minimal effort and maximum impact!

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

The importance of safeguarding system credentials cannot be overstated in the realm of security. Unauthorized access to these credentials undermines the foundational principle of authentication and can lead to severe data breaches. It's essential to ensure that secrets are not embedded in source code, as security is only as strong as its weakest link.

 

This presentation covers the implementation of a robust secret detection system that leverages TruffleHog, an open-source tool, to perform scheduled and integrated preventive scans across GitHub and Azure DevOps repositories. The system is designed to scan on a scheduled basis and in response to specific triggers such as pull requests or pushes to specific branches, ensuring real-time detection and prevention of secret leaks.

 

The infrastructure, built using Terraform and cloud-based services, is capable of handling large-scale operations, scanning terabytes of data, and accommodating the unique challenges inherent in rolling out such a comprehensive initiative within an organizational framework.

 

At the end of this talk, attendees will have have learnt how to construct an efficient and automated secrets detection and prevention program at scale and secrets management strategies to help with remediation. The discussion will cover practical considerations for implementation, including the deployment of Infrastructure as Code (IaC), secret management strategies, and the integration of monitoring services. All of the knowledge shared in this talk will be applicable immediately after.


Speakers
avatar for Yassine Ilmi

Yassine Ilmi

Product Security Architect, Thomson Reuters
Yassine Ilmi is a seasoned Product Security Architect at Thomson Reuters, where he spearheads all aspects of product security. With a comprehensive background in information security, risk management, and secure software development, Yassine has made significant contributions to establishing... Read More →
avatar for Arbër Salihi

Arbër Salihi

Senior Product Security Engineer, Thomson Reuters
Arbër Salihi is a Senior Product Security Engineer at Thomson Reuters, where he works in the Product Security team focusing on container security, software supply chain security, and application security. As part of his role, Arbër and his team members collaborate closely with all... Read More →


Thursday June 27, 2024 11:30am - 12:15pm WEST
Feedback form isn't open yet.

Attendees (4)