Field report 14 · Identity and security

Secrets do not belong in the process list

How to automate the handling of keys and credentials without exposing them along the way.

Status
From practice Experience from our own operations.
Published
Publisher
SIMO GmbH, Aschaffenburg, Germany

Starting questionHow do we automate the handling of keys and credentials without exposing them?

What we experienced

While automating a secrets vault, passing the value through standard input failed. The tool only knows two ways: interactive input or a command-line argument. The argument would have been visible in the process list and the shell history.

A review found the same weakness in a second script. The fix was the direct programming interface, with the value passed through standard input.

What it means for business architecture

Security tools are built for people or for machines, rarely for both. Automation needs the route designed for machines.

Learnings

  1. Familiar patterns from other tools do not apply everywhere. Assumptions need checking.
  2. One finding is a reason to check similar places on purpose.
  3. A leak without symptoms is still a leak.
  • secrets
  • automation
  • secrets vault
  • security

Matching consulting service

From the Lab into consulting.

What we trial in the Lab, SIMO GmbH puts into practice as consultants: Business Data Strategy & Architecture for AI, following the Zero Friction Data Flow principle. These services relate to this report:

45 minutes, free of charge, with the SIMO GmbH consultants. The form is on simo-online.com.

More reports on the same topic