EuroPython 2016

Behind Closed Doors: Managing Passwords in a Dangerous World

Speaker(s) Noah Kantrowitz

Secrets come in many forms, passwords, keys, tokens. All crucial for the operation of an application, but each dangerous in its own way. In the past, many of us have pasted those secrets in to a text file and moved on, but in a world of config automation and ephemeral microservices these patterns are leaving our data at greater risk than ever before.

New tools, products, and libraries are being released all the time to try to cope with this massive rise in threats, both new and old-but-ignored. This talk will cover the major types of secrets in a normal web application, how to model their security properties, what tools are best for each situation, and how to use them with major web frameworks.

in on Monday 18 July at 16:00 See schedule

Do you have some questions on this talk?

New comment