Valentino Stoll
speaker
350 appearances
6 recordings
1 series
first heard Sep 2024
last heard Oct 2024
Valentino Stoll’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
We use a lot of AWS stuff to handle a lot of the... They have a secrets management deal in there. Yeah, and I think it may even be isolated from the main environments too and handled that way in an isolated environment. We use Docker as well, so It could be like an isolated container that then feeds back into the other container.
Yeah, I think so. Something like that. It may even be one step further where it's in AWS and then at like run run time. It's like the secrets are loaded into the app's memory for the particular use case. I don't really know all of the details, to be honest. I'm not on the infrastructure team. Everyone's like, well, we have to rotate keys. And that's definitely an easy process for us.
But yeah, we have some command line that does it. It's not just like changing the environment variable.
Yeah, that makes me curious because I think at one time we were using... I forget what HashRocket's product is. We ended up moving away from that. Yeah, I don't know. We were using some vendor for doing the secrets management. But yeah, having a command line or some kind of central place, a command line doesn't even need to...
be your UX of choice, but just having the centralized place where all of that access points happen, it definitely helps isolate and track, to be honest, who's touching what and changing it. I don't know if Doppler has those kind of features as far as tracking changes and getting the full logs and things like that, but that's definitely been super valuable.
Yeah. That's always makes me wonder, like, cause there's two parts of this, right? Like we have the secrets and then there's like the whole encryption aspect of it, which is his own separate beast of the discussion.
Well, what you're, I mean, ultimately what you're using a lot of the secrets for, I would imagine is to encrypt something or, or even to, yeah, I mean, to encrypt stuff.
Yeah, that's all. I always want to, one of the biggest things that, uh, I always hope for when I'm like getting a new vendor, like access token or whatever it may be, is that they like have some kind of like, you know, whitelist stability with like either their domain or
like a domain key or some kind of identifier that can be like, you know, securely matched when the handshake is made using their service from whatever server that you end up using. In my experience, it's honestly very rare that that actually happens.
That makes a lot of sense, you saying that your customers mostly store access tokens because most vendors don't give you that whitelist ability and handshake process, which is very important. I think it causes a lot of the breaches when it's not there.
Is there an open standard that is following this process or no?
So I love this. You have this great secrets for all page on Doppler. I link to and it's really great. Kind of helps you quickly assess your risk exposure based on your team size. You go through kind of like a quick calculation. Oh, we have like this number of projects, estimate number of secrets per project. Then you have a certain number of environments, right? So it's a multiplier.
And then you have, you know, a multiplier over the number of team members too. And so those quickly add up and you make a great point, like, you know, the malicious actor, they only need one, right, of the thousands that adds up to. And so I'm curious, like, you know, from the, like the whole point kind of is like risk assessment and remediation, right? And like, do you find that, you know,
focusing on the that risk aspect is just as important as like kind of the secret storage management mechanisms yeah they go they go hand in hand for sure you need something that developers are going to want to use that is secure when they do use it and you want to think about that risk like
So I'm curious, like, if you have any tools or, like, what would you do to kind of, like, visualize the, like,
know organizational structure in the in combination like it's more than just like secrets management it seems right uh like how do you how do you personally visualize like the security aspects surrounding the secrets and who accesses them and things like that uh to understand kind of what is happening and where the access points are yeah great question uh truly a great question um
What inspired you to start Dropler? Where does this story start? I'm curious where your background is and how you're like, oh, we need a better secrets manager.
So I'm curious, like, what are some common, like, preventable breaches that you've encountered? And like, How can developers avoid them, right?
Yeah, I think you make a great point. I mean, being able to respond quickly is definitely like high up on that list and being able to remediate that as fast as possible because it will happen. Like you kind of just like have to go with eventually something will happen and you have to like just stop it as soon as possible.
And in my experience, just having that ability to move quickly to rotate things around has been like the best thing defense in the long run, at least from minimizing damage. Right.
Showing 61–80 of 350 · page 4 of 18
← Previous
Next →