#secretmanagement — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #secretmanagement, aggregated by home.social.
-
Infinito.Nexus 14.2: OpenBao introduces advanced secrets management
Infinito.Nexus 14.2 introduces OpenBao for secrets management, giving applications and services a dedicated way to handle credentials, API keys and machine identities. OpenBao integrates with the existing Infinito.Nexus identity and deployment model. Users can authenticate through Keycloak, or LDAP when OpenLDAP is deployed, while services and automation use their own AppRole identities. Credentials are automatically changed on every deployment, and the OpenBao root token is not retained after the initial setup. The release also adds recovery handling, automatic unsealing after restarts, optional internal PKI and Prometheus alerts when OpenBao is sealed or unreachable. In addition, 14.2 fixes LDAP administration in LAM, improves Docker Swarm handling of existing networks, adds role-local Prometheus alert rules, restores video recording for manually created Playwright contexts and updates pgAdmin to 9.18. […] -
Not much to read here, only the first section. You do not need anything else to understand the state of #infosec for so many orgs... https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach | #APISecurity #SecretManagement #securecoding
-
Not much to read here, only the first section. You do not need anything else to understand the state of #infosec for so many orgs... https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach | #APISecurity #SecretManagement #securecoding
-
Not much to read here, only the first section. You do not need anything else to understand the state of #infosec for so many orgs... https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach | #APISecurity #SecretManagement #securecoding
-
Not much to read here, only the first section. You do not need anything else to understand the state of #infosec for so many orgs... https://scotthelme.co.uk/no-hacking-required-manchester-airports-group-data-breach | #APISecurity #SecretManagement #securecoding
-
Trouble with secret management grows when shared long-lived keys spread beyond anyone's inventory.
#SecretManagement #Cybersecurity #ProfessionalGrowth -
It’s the final day of InCyber! 🚀🇫🇷
If you haven’t stopped by Stand 44 yet, this is your last chance to grab some Passbolt merch.
For more info: https://www.passbolt.com/?utm_campaign=40961189-2026_Events&utm_source=InCyber
#Passbolt #InCyber #cybersecurity #opensource #secretmanagement
-
It’s the final day of InCyber! 🚀🇫🇷
If you haven’t stopped by Stand 44 yet, this is your last chance to grab some Passbolt merch.
For more info: https://www.passbolt.com/?utm_campaign=40961189-2026_Events&utm_source=InCyber
#Passbolt #InCyber #cybersecurity #opensource #secretmanagement
-
It’s the final day of InCyber! 🚀🇫🇷
If you haven’t stopped by Stand 44 yet, this is your last chance to grab some Passbolt merch.
For more info: https://www.passbolt.com/?utm_campaign=40961189-2026_Events&utm_source=InCyber
#Passbolt #InCyber #cybersecurity #opensource #secretmanagement
-
It’s the final day of InCyber! 🚀🇫🇷
If you haven’t stopped by Stand 44 yet, this is your last chance to grab some Passbolt merch.
For more info: https://www.passbolt.com/?utm_campaign=40961189-2026_Events&utm_source=InCyber
#Passbolt #InCyber #cybersecurity #opensource #secretmanagement
-
We are live at InCyber in Lille! 👋🏼🇫🇷
Stop by Stand F44 to learn more about Passbolt, and chat over a coffee (or a beer after 17:00 PM! 🍻).
👉🏼 If you haven't secured your spot yet, there is still time to grab a pass: https://europe.forum-incyber.com/
#Passbolt #InCyber #Cybersecurity #OpenSource #SecretManagement -
We are live at InCyber in Lille! 👋🏼🇫🇷
Stop by Stand F44 to learn more about Passbolt, and chat over a coffee (or a beer after 17:00 PM! 🍻).
👉🏼 If you haven't secured your spot yet, there is still time to grab a pass: https://europe.forum-incyber.com/
#Passbolt #InCyber #Cybersecurity #OpenSource #SecretManagement -
We are live at InCyber in Lille! 👋🏼🇫🇷
Stop by Stand F44 to learn more about Passbolt, and chat over a coffee (or a beer after 17:00 PM! 🍻).
👉🏼 If you haven't secured your spot yet, there is still time to grab a pass: https://europe.forum-incyber.com/
#Passbolt #InCyber #Cybersecurity #OpenSource #SecretManagement -
We are live at InCyber in Lille! 👋🏼🇫🇷
Stop by Stand F44 to learn more about Passbolt, and chat over a coffee (or a beer after 17:00 PM! 🍻).
👉🏼 If you haven't secured your spot yet, there is still time to grab a pass: https://europe.forum-incyber.com/
#Passbolt #InCyber #Cybersecurity #OpenSource #SecretManagement -
Demain, direction le forum InCyber à Lille ! 🛡️
Retrouvez-nous sur le stand F44 pour parler gestion de mots de passe & secrets, open-source et auto-hébergement.
On a aussi fait le plein de goodies pour l'occasion.
À demain ! 👋
Pour en savoir plus: https://europe.forum-incyber.com/acces/#infos
#Passbolt #InCyber #CyberSec #Lille #cybersecurity #opensource #secretmanagement
-
Demain, direction le forum InCyber à Lille ! 🛡️
Retrouvez-nous sur le stand F44 pour parler gestion de mots de passe & secrets, open-source et auto-hébergement.
On a aussi fait le plein de goodies pour l'occasion.
À demain ! 👋
Pour en savoir plus: https://europe.forum-incyber.com/acces/#infos
#Passbolt #InCyber #CyberSec #Lille #cybersecurity #opensource #secretmanagement
-
Demain, direction le forum InCyber à Lille ! 🛡️
Retrouvez-nous sur le stand F44 pour parler gestion de mots de passe & secrets, open-source et auto-hébergement.
On a aussi fait le plein de goodies pour l'occasion.
À demain ! 👋
Pour en savoir plus: https://europe.forum-incyber.com/acces/#infos
#Passbolt #InCyber #CyberSec #Lille #cybersecurity #opensource #secretmanagement
-
Demain, direction le forum InCyber à Lille ! 🛡️
Retrouvez-nous sur le stand F44 pour parler gestion de mots de passe & secrets, open-source et auto-hébergement.
On a aussi fait le plein de goodies pour l'occasion.
À demain ! 👋
Pour en savoir plus: https://europe.forum-incyber.com/acces/#infos
#Passbolt #InCyber #CyberSec #Lille #cybersecurity #opensource #secretmanagement
-
"Khám phá CruxVault - Công cụ quản lý bí mật Git-like đầu tiên trên máy cục bộ!
- Mã hóa bí mật cục bộ
- Lưu trữ bí mật với kiểm soát phiên bản
- CLI giống Git (crux init, crux commit, crux status)
- Thẻ môi trường (dev/staging/prod)
Hoàn toàn ngoại tuyến, không phụ thuộc vào cloud!
#CruxVault #SecretManagement #LocalFirst #GitLike #DevTool #CôngCụLậpTrình #QuảnLýBíMật"https://www.reddit.com/r/SideProject/comments/1oq7tgt/built_cruxvault_localfirst_gitlike_secret/
-
This is why you should not hard-code credentials in your source code, but use env. vars or credential managers.
Looks like someone sent me a mail via a python script. The script had an issue which let the mail content to be the script itself, which contains a token.
(Or this is phishing wanting me to try the token)
-
This is why you should not hard-code credentials in your source code, but use env. vars or credential managers.
Looks like someone sent me a mail via a python script. The script had an issue which let the mail content to be the script itself, which contains a token.
(Or this is phishing wanting me to try the token)
-
This is why you should not hard-code credentials in your source code, but use env. vars or credential managers.
Looks like someone sent me a mail via a python script. The script had an issue which let the mail content to be the script itself, which contains a token.
(Or this is phishing wanting me to try the token)
-
This is why you should not hard-code credentials in your source code, but use env. vars or credential managers.
Looks like someone sent me a mail via a python script. The script had an issue which let the mail content to be the script itself, which contains a token.
(Or this is phishing wanting me to try the token)
-
I released params2env, a Go based CLI tool I've built that reads AWS SSM Parameter Store values and sets them as environment variables.
The tool can create, modify, and delete parameters, and supports optional cross-region replication for redundancy.
Read more on my blog: https://dominik.wombacher.cc/posts/params2env-aws-ssm-parameter-store-to-environment-variables.html
#AWS #Go #GoLang #CLI #OpenSource #ParameterStore #DevOps #SecretManagement
-
I released params2env, a Go based CLI tool I've built that reads AWS SSM Parameter Store values and sets them as environment variables.
The tool can create, modify, and delete parameters, and supports optional cross-region replication for redundancy.
Read more on my blog: https://dominik.wombacher.cc/posts/params2env-aws-ssm-parameter-store-to-environment-variables.html
#AWS #Go #GoLang #CLI #OpenSource #ParameterStore #DevOps #SecretManagement
-
I released params2env, a Go based CLI tool I've built that reads AWS SSM Parameter Store values and sets them as environment variables.
The tool can create, modify, and delete parameters, and supports optional cross-region replication for redundancy.
Read more on my blog: https://dominik.wombacher.cc/posts/params2env-aws-ssm-parameter-store-to-environment-variables.html
#AWS #Go #GoLang #CLI #OpenSource #ParameterStore #DevOps #SecretManagement
-
🚀🎉 Hold the presses! #OpenBao adds "Namespaces" to its secret manager, enabling isolated environments for your secrets. 🤔 Finally, a solution to the problem of "Where did I put my secrets again?" 😅 Thanks, OpenBao, for making secret management feel like a game of hide-and-seek with a twist! 🙄🔍
https://openbao.org/blog/namespaces-announcement/ #Namespaces #SecretManagement #IsolatedEnvironments #CyberSecurity #HackerNews #ngated -
🚀🎉 Hold the presses! #OpenBao adds "Namespaces" to its secret manager, enabling isolated environments for your secrets. 🤔 Finally, a solution to the problem of "Where did I put my secrets again?" 😅 Thanks, OpenBao, for making secret management feel like a game of hide-and-seek with a twist! 🙄🔍
https://openbao.org/blog/namespaces-announcement/ #Namespaces #SecretManagement #IsolatedEnvironments #CyberSecurity #HackerNews #ngated -
🚀🎉 Hold the presses! #OpenBao adds "Namespaces" to its secret manager, enabling isolated environments for your secrets. 🤔 Finally, a solution to the problem of "Where did I put my secrets again?" 😅 Thanks, OpenBao, for making secret management feel like a game of hide-and-seek with a twist! 🙄🔍
https://openbao.org/blog/namespaces-announcement/ #Namespaces #SecretManagement #IsolatedEnvironments #CyberSecurity #HackerNews #ngated -
🚀🎉 Hold the presses! #OpenBao adds "Namespaces" to its secret manager, enabling isolated environments for your secrets. 🤔 Finally, a solution to the problem of "Where did I put my secrets again?" 😅 Thanks, OpenBao, for making secret management feel like a game of hide-and-seek with a twist! 🙄🔍
https://openbao.org/blog/namespaces-announcement/ #Namespaces #SecretManagement #IsolatedEnvironments #CyberSecurity #HackerNews #ngated -
"The 18-point secrets management checklist"
https://www.hashicorp.com/en/blog/the-18-point-secrets-management-checklist
-
"The 18-point secrets management checklist"
https://www.hashicorp.com/en/blog/the-18-point-secrets-management-checklist
-
"The 18-point secrets management checklist"
https://www.hashicorp.com/en/blog/the-18-point-secrets-management-checklist
-
"The 18-point secrets management checklist"
https://www.hashicorp.com/en/blog/the-18-point-secrets-management-checklist
-
....aaaaaand #OpenBao (the fork of #Hashicorp #Vault) is on its way to @opensuse #Tumbleweed in the latest version 2.2.1. Since 2.2.0 the webui is included in OpenBao, so this can be a full replacement for Vault!
Looking forward to doing more testing with it!
In case you want to try it out, here is a #vagrant #libvirt setup using #Ansible to prepare an OpenBao server VM and a client using a secret.
https://codeberg.org/johanneskastl/openbao_vagrant_libvirt_ansible -
....aaaaaand #OpenBao (the fork of #Hashicorp #Vault) is on its way to @opensuse #Tumbleweed in the latest version 2.2.1. Since 2.2.0 the webui is included in OpenBao, so this can be a full replacement for Vault!
Looking forward to doing more testing with it!
In case you want to try it out, here is a #vagrant #libvirt setup using #Ansible to prepare an OpenBao server VM and a client using a secret.
https://codeberg.org/johanneskastl/openbao_vagrant_libvirt_ansible -
....aaaaaand #OpenBao (the fork of #Hashicorp #Vault) is on its way to @opensuse #Tumbleweed in the latest version 2.2.1. Since 2.2.0 the webui is included in OpenBao, so this can be a full replacement for Vault!
Looking forward to doing more testing with it!
In case you want to try it out, here is a #vagrant #libvirt setup using #Ansible to prepare an OpenBao server VM and a client using a secret.
https://codeberg.org/johanneskastl/openbao_vagrant_libvirt_ansible -
....aaaaaand #OpenBao (the fork of #Hashicorp #Vault) is on its way to @opensuse #Tumbleweed in the latest version 2.2.1. Since 2.2.0 the webui is included in OpenBao, so this can be a full replacement for Vault!
Looking forward to doing more testing with it!
In case you want to try it out, here is a #vagrant #libvirt setup using #Ansible to prepare an OpenBao server VM and a client using a secret.
https://codeberg.org/johanneskastl/openbao_vagrant_libvirt_ansible -
GitHub is shaking up code security after 39 million secrets leaked—now every team can access standalone tools backed by AI and major cloud partners. Curious how this could reshape digital protection?
https://thedefendopsdiaries.com/githubs-security-tools-expansion-a-new-era-in-software-protection/
#githubsecurity
#softwareprotection
#secretmanagement
#cybersecuritytools
#infosec -
GitHub is shaking up code security after 39 million secrets leaked—now every team can access standalone tools backed by AI and major cloud partners. Curious how this could reshape digital protection?
https://thedefendopsdiaries.com/githubs-security-tools-expansion-a-new-era-in-software-protection/
#githubsecurity
#softwareprotection
#secretmanagement
#cybersecuritytools
#infosec -
Video Intro to Secret Management with PowerShell http://dlvr.it/TJF0J3 via PlanetPowerShell #PowerShell #SecretManagement #Microsoft #Automation
-
Video Intro to Secret Management with PowerShell http://dlvr.it/TJF0J3 via PlanetPowerShell #PowerShell #SecretManagement #Microsoft #Automation
-
Video Intro to Secret Management with PowerShell http://dlvr.it/TJF0J3 via PlanetPowerShell #PowerShell #SecretManagement #Microsoft #Automation
-
Video Intro to Secret Management with PowerShell http://dlvr.it/TJF0J3 via PlanetPowerShell #PowerShell #SecretManagement #Microsoft #Automation
-
@nixos_org 🎉 took me 12 days to finally understand how this works & setup but I finally got a working secret management config! Check this out https://codeberg.org/dminca/nix-config/src/branch/main/secrets/example.yaml
#security #secretManagement #nix #nixDarwin #x86_64darwin #aarm64darwin
-
@nixos_org 🎉 took me 12 days to finally understand how this works & setup but I finally got a working secret management config! Check this out https://codeberg.org/dminca/nix-config/src/branch/main/secrets/example.yaml
#security #secretManagement #nix #nixDarwin #x86_64darwin #aarm64darwin
-
First @nixos_org challenge by the course of a month trying to get acquainted with #nix : secret management .
Seems there’s absolutely no ‘batteries-included’ way to have this implemented the proper way, instead people have to come up with their own ‘hacks’ so-to-speak to get something feasible working…
#nixos #nix #secretManagement #encryption #security #x86_64darwin #aarm64darwin
-
First @nixos_org challenge by the course of a month trying to get acquainted with #nix : secret management .
Seems there’s absolutely no ‘batteries-included’ way to have this implemented the proper way, instead people have to come up with their own ‘hacks’ so-to-speak to get something feasible working…
#nixos #nix #secretManagement #encryption #security #x86_64darwin #aarm64darwin
-
First @nixos_org challenge by the course of a month trying to get acquainted with #nix : secret management .
Seems there’s absolutely no ‘batteries-included’ way to have this implemented the proper way, instead people have to come up with their own ‘hacks’ so-to-speak to get something feasible working…
#nixos #nix #secretManagement #encryption #security #x86_64darwin #aarm64darwin
-
First @nixos_org challenge by the course of a month trying to get acquainted with #nix : secret management .
Seems there’s absolutely no ‘batteries-included’ way to have this implemented the proper way, instead people have to come up with their own ‘hacks’ so-to-speak to get something feasible working…
#nixos #nix #secretManagement #encryption #security #x86_64darwin #aarm64darwin
-
I just wrote a new blog post, Preventing Secrets in Code! #appsec #secrets #secretmanagement
https://shehackspurple.ca/2023/04/10/preventing-secrets-in-code/
-
I just wrote a new blog post, Preventing Secrets in Code! #appsec #secrets #secretmanagement
https://shehackspurple.ca/2023/04/10/preventing-secrets-in-code/
-
I just wrote a new blog post, Preventing Secrets in Code! #appsec #secrets #secretmanagement
https://shehackspurple.ca/2023/04/10/preventing-secrets-in-code/
-
I just wrote a new blog post, Preventing Secrets in Code! #appsec #secrets #secretmanagement
https://shehackspurple.ca/2023/04/10/preventing-secrets-in-code/
-
I‘m happy to announce the publication of my #PowerShell template module for #SecretManagement Extensions on GitHub. It enables the fast creation of new SecretManagement Extensions, including many best practices and (most important) a ReadMe which describes all pitfalls I’ve fallen into and the tricks to avoid this. All learned the hard way creating SecretManagement.NetwrixPasswordSecure 😋. If only one new extension based on the template is created the work was worth it.
https://github.com/Callidus2000/SecretManagement.ExtensionTemplate
-
I‘m happy to announce the publication of my #PowerShell template module for #SecretManagement Extensions on GitHub. It enables the fast creation of new SecretManagement Extensions, including many best practices and (most important) a ReadMe which describes all pitfalls I’ve fallen into and the tricks to avoid this. All learned the hard way creating SecretManagement.NetwrixPasswordSecure 😋. If only one new extension based on the template is created the work was worth it.
https://github.com/Callidus2000/SecretManagement.ExtensionTemplate
-
I‘m happy to announce the publication of my #PowerShell template module for #SecretManagement Extensions on GitHub. It enables the fast creation of new SecretManagement Extensions, including many best practices and (most important) a ReadMe which describes all pitfalls I’ve fallen into and the tricks to avoid this. All learned the hard way creating SecretManagement.NetwrixPasswordSecure 😋. If only one new extension based on the template is created the work was worth it.
https://github.com/Callidus2000/SecretManagement.ExtensionTemplate
-
I‘m happy to announce the publication of my #PowerShell template module for #SecretManagement Extensions on GitHub. It enables the fast creation of new SecretManagement Extensions, including many best practices and (most important) a ReadMe which describes all pitfalls I’ve fallen into and the tricks to avoid this. All learned the hard way creating SecretManagement.NetwrixPasswordSecure 😋. If only one new extension based on the template is created the work was worth it.
https://github.com/Callidus2000/SecretManagement.ExtensionTemplate
-
Is there an 'easy' way to call private #PowerShell functions from nested modules?
I've got my module A with the nested module B. Now I've got a function (f) which is needed/usable from both A&B but makes no sense as a public function. Currently I've made it available as public A\f and can access it from everywhere.
And the answer 'don't use nested modules' is sadly not acceptable as this is the design pattern for #SecretManagement extensions 😒
-
Is there an 'easy' way to call private #PowerShell functions from nested modules?
I've got my module A with the nested module B. Now I've got a function (f) which is needed/usable from both A&B but makes no sense as a public function. Currently I've made it available as public A\f and can access it from everywhere.
And the answer 'don't use nested modules' is sadly not acceptable as this is the design pattern for #SecretManagement extensions 😒