Defeating Secrets Sprawl: The Power of Vaultless Secrets Management – Oded Hareven, Akeyless Security
The move to the cloud, the dominance of containerization in development and new DevOps methodology have led to a rise in machines – including processes, scripts, applications and containers and databases, among others. These machines require authentication and authorization continuously via secrets (credentials, certificates and keys) and must be continuously accessible. These secrets have consequently been embedded in vulnerable code, scripts, configuration files and CI/CD tools – which is generally called “secrets sprawl.” This sprawl has led to a rise of increasingly prominent hacks and leaks. While secrets vaults were introduced to solve this problem, these vaults are unwieldy, and their complexity can further contribute to sprawl. A remedy is vaultless secrets management: SaaS-based, deployment-free, efficient and scalable. Akeyless’ Vaultless™ approach and DFC™ technology offers this solution, tailored to modern development. Oded explains the role of vaultless secrets management within a multi-layered security approach against emerging digital threats.
Transcript
This is Textron tv. Hey, everyone. Welcome back here to techron tv.
I am, uh, happy to be joined today by ODed Harvin. Harvin, excuse me, co-founder, c e o of Aquila Security, ODed. I've mangled your last name, I apologize.
That's perfect. Pronouncing correctly for us. Perfectly fine.
You know, Hebrew, it sounds like actually German. It's Hal Evan. Hi, Evan.
You're doing fine. That's fine. Okay.
Well, I, I do my best anyway. ODed, we're gonna talk a latte about secrets management and stuff like that. But before we do, I wanted to give people a little bit of your background and a little bit, you know, not everyone out here knows a keyless security, so let's, let's, you know, go hit those two right off the bat.
Yeah, Sure. Thank you for having me, Alan. I'm, I'm very, um, excited to be here with you.
Um, so my background, uh, Israeli Defense Forces, uh, cybersecurity unit. I've been there for, um, uh, quite a while, um, mainly around identity management, oc, uh, and things of such infrastructure, DevOps, automation. Back in the days where we didn't, we, we didn't really call it DevOps obviously.
Um, and then after that, I've done, uh, my share with, uh, ca technology. Joined there as a solution architect, and later on as a senior product, uh, project manager, uh, again, cybersecurity projects, um, here, um, back then in Israel, before I relocated to New Jersey, uh, that was back then. After that, I had some while as a product management in, uh, B two C business, a company, they move it later acquired by Intel in the public transportation.
That, that was my, my share with, uh, B two C. Uh, definitely something that I encourage people to taste, you know, not just the cybersecurity and B two B business, the enterprise business that we're at rather than, you know, uh, there's a lot of things that you can obviously, you know, learn and to have and, and, and have some synthesis between all of those worlds. And at five years old, together with my two partners, uh, uh, two partners and the two co-founders of the company, uh, three of us have, uh, basically established aquilos.
Uh, this is, uh, this is it. Excellent. So, you know, I've, I've interviewed hundreds of founders, co-founders over the years.
I've never met a co-founder who wasn't passionate or a successful co-founder who wasn't passionate about their company and the company's mission, that somehow what they were doing was making the world better. It may not be curing cancer or making world peace or anything like that, but in some small way, it makes someone's life better. Tell me what your passion is for a keyless security.
I'll tell you, there's a major problem for a long, long time in cybersecurity around credentials, uh, lately, also certificates, but also encryption keys. All of those objects that we call, you know, secrets. Basically, this is what we do, secrets management.
Uh, for me, it was very intriguing, uh, when we started to look at this, you know, the technology that, um, the c t o, our co-founder, uh, brought, um, basically invented called D F C distributed fragments, cryptography, uh, in a nutshell that technology has the ability to encrypt the creep and sign, uh, whatever needed, uh, using fragments of encryption keys without ever combining them. So having this technology together with the, the need and the requirements of cloud, which is having, uh, the ability to protect objects in a, a decentralized, uh, distributed world where you have lots of regions environments and everything is well automated together with a trend of machines in which we'll talk about today. Uh, having that altogether, that was, um, that's what opportunity, personally for me, you know, to fix something that was broken for a long, long time in cybersecurity around credential certificates and keys, and actually how to manage them in one system platform to provide all of those solutions from one location.
So that was back in the days when I was in the Israeli Defense Forces. I've had, uh, specifically for those tasks today that we provide within one platform. We've had 12 people, uh, just to run all of those different, you know, tasks that today one person could do from one, one platform.
So, all of those kind things, all of the kind of things, uh, this is basically things that make me joy, you know, to fix what was broken for a long time. Excellent. Good stuff.
You know, the whole category of secrets management. Sure. Right?
I, look, I, I'll be honest, I, I first became really aware and, and got my head wrapped around it as a result of HashiCorp Right. And Vault and all of that stuff. I don't know That.
Yeah, I don't know that now. You never heard of him, I'm sure, but, you know, since then, and, and, and I realized then what a big, what a big market, what a big problem. What a big issue this is, right, in, in, in our cybersecurity, but not everyone out here is I got a lot of DevOps people who maybe are not as familiar with secrets.
Sure. Uh, cloud people, a you know, they're all tech people, but they're not. How would you, how do you explain the whole secrets?
It's not, we're not talking about whispers. We're not talking about no, you know, keeping secrets. When we talk about secrets and secrets management, how do you explain that to people?
Sure. And yes, of course, we're not even talking about business secrets, right? We're talking about specifically about identity related secrets, right?
And data related secrets. Um, but let, let me explain it this way. There's data out there, right?
And you need to access that data, right? In order to access that data, you require a password. An a p i key, it can be an s s h key.
Well, I can go on and on with all kind of tech, uh, terms, but basically all kind of objects that you're using in order to access that data, okay? Either because of authentication or because of encrypted, right? It's encrypted data.
So you need an, uh, encryption key in order to decrypt it, et cetera. Okay? So those are different types of objects that help you to access a certain data.
This is the generalized, uh, generalized terminology, okay? Or the definition, but it's not everything. What's missing here is the context of what's happened in the last years, which is the containerization trend, cloud transformation, obviously, DevOps, automation, all of that all together, basically brought us into a world where we have millions of machines.
When I say machines, I mean automated processes. It can be containers, it can be lambda functions, or whatever microservices that exist, right? Every automated process, every machine, in that sense, they require right communication between them and like humans, they need to say, hi, this is who I am.
I am who I am, and believe me, right? I have some kind of, uh, uh, validity check that I need to pass with authentication. And the other party, another machine need, uh, needs to trust it.
So this authentication process requires lots of secrets. Now, as I've said, those trends basically brought us into a world where you have millions of those machines. And automation also brought us to a world in which each machine must have a lot of those secrets, because it needs to not just authenticate to the database, right?
Think of a management console that need to communicate with a lot of different other servers, right? So all of those secrets were found and still are, unfortunately, within configuration file source code within automation tools, right? And this has nothing to do with the older problem of the privileged access, right?
That it was kind of specific to humans. So now we're talking about a trend that have happened in the last few years that actually took the, I would call it smaller problem of privileged access management. And now you're talking about a velocity, right?
A, a, a major boom of secrets that are now being used and obviously, uh, have the ability to compromise, uh, a whole organization and to be preached. Love it. I hope this is like more clear, but let me know.
Yeah, no, it is, it is, it is. Another concept I want us to hit here is the vaulted secure, uh, secrets versus vault list. Yeah, of course.
So this is basically, um, um, generational transformation that we're seeing in the past a few years. Obviously, akilis is the one to provide, uh, the newest solution among all of that, the third generation of volts. But let me explain.
If the first generation was to have your own secrets, credentials, certificates, keys within those static places, which means configuration files against source code, uh, automation tools, et cetera. Now, the second generation was to have all of those to be centralized within a certain vault, right? You've mentioned one of the vendors.
There are all kind of other solutions in the, the market also that are into centralizing those vaults. But mainly you need to make sure within that second generation, you've had to make sure that you are, uh, deploying that system. You are maintaining that system because it is, it needs to kept to be kept within your facility, right?
So if you are the customer, if you're the enterprise, you must have those secrets within it, right? And you basically need to replicate them between different regions and different cloud providers, right? So if now you need to have them, right?
The problem was to basically have them within multiple environments and all that time, because secrets are mission critical. You need to have them highly available. So suddenly you'll find yourself with those two second generation, uh, vaults, you found yourself basically managing vaults instead of managing your secrets, right?
Because of the, of the nature of having them to be mission critical. If your secrets are not available, you production is not working. So what we provided here, uh, is the third generation, which means you can be busy with managing your secrets and not managing your vote.
Excuse me. This means the vote list approach basically means that we're managing the vote for you using a SaaS, uh, a SaaS service, which basically leveraging our D F C technology that has the ability to ensure zero knowledge, right? We're able to encrypt using fragments of encryption keys.
Those fragments are never combined. You as a customer have your own fragment. And that means that even Aquilos doesn't have access to those, uh, secrets to those fragments.
Uh, so we are basically doing all of that work for you. You don't have to deploy, you don't have to maintain, we're keeping your secrets, uh, with 24 7 and, uh, four, nine availability without you needing to replicate them. And to be worried about what do I do when I have another environment and I need to manage my secrets?
That's it, basically. I love it. You know, I've been in security 25 plus years myself.
There was a time where everything in security was based on agents, and then some companies started advertising agentless security. Yeah. Right?
But it really wasn't agentless security. There was, there was still an agent. They just didn't call it an agent.
They gave it another name, but they snuck it in. It was still a piece of software running on it. Yeah, I I, I remember that period.
You remember those years. So listening to you here, I just wanna make sure I, it sounds like what we're doing is in with this third generation of, of, uh, secrets management, we're taking the vault out of the domain of the, of the user of the organization. And, and a company like a keyless is, is providing, let's say a SaaS-based vault, but it's where, where you guys have put a lot more armor and, or a lot more thought around protecting these secrets.
So it's a Exactly. It's a, it's a, it's a more secure vault, and it's, and it, and it doesn't reside if you get hit on your infrastructure that it's still, you know, segregated from that. Yeah.
I can tell you even more than this, the zero knowledge protection based on our D F C technology, right? All of those fragments that are never combined, et cetera, they, this creates a situation where even if the government are asking a keyless as a service provider for your secrets, right? Even if the government are asking us to provide them with your encryption keys, the only thing we can provide them are is basically sand it's stand of either fragments that you, they cannot do nothing with it because you have another fragment, right?
Right. And they cannot complete it. And it's basically encrypted secrets in which they cannot open.
So you're protected not just by supply chain attack, you know, from us, you are also protected by government access, uh, and, and all of sorts. So you're getting here a high level of security and this combination of D F C and SaaS, right? This is the enablement of how, what we call the vote approach or our vote platform.
I love it. It's great. Alright.
And, and you know, this is sort of state of the art right now, right? When we talk about secrets management, cloud, multi-cloud, hybrid cloud, et cetera. Yeah.
We see great traction, uh, coming from, you know, uh, uh, you name it, uh, big brands, uh, pharmaceutical retailers, financials, insurance. Everyone are interested, uh, with secrets management, with managing their secrets better. Whenever a company faces this DevOps automation coming up with security challenges, uh, combined with regions, environments, you know, complexity of their infrastructure, they immediately, uh, face the problem of how do I manage my secrets?
Because they have suddenly so much like every DevOps person that you'll meet, and you can ask them, you know, how many secrets, how many credentials, how many certificates you're managing, and they're like, I'm losing my hands and legs, right? I'm, I'm losing it. So I know that I need to have it managed.
Right? And this is where usually they take their first steps with, uh, whatever solutions that they can find, and very quickly they understand that they need an enterprise grade solution that is able to provide them, you know, the level of availability, the level of, of, you know, zero maintenance to have t c o to be extremely reduced, uh, with comparing to many other solutions. I got it.
This has been fantastic. Oh dude, I'd like to use the rest of our time. And we're running low.
So people heard this, they said, yes, this sounds what I, where I want to be. I want to, you know, have the latest, greatest here. How do they, how do they interact with a keyless?
How do they get started? Well, they're easy. Well, first of all, they can do them.
Uh, they can, they can do it by their own, that's fine. Our SaaS is open and, uh, uh, basically free to use for community version. That's not a problem.
io just to uh, open up a new user. Our documentation is open, everything is there. Uh, but they can do more than this if they're really interested, obviously to explore the enterprise version and, uh, the whole features to be opened, uh, for them to be used.
And they're mostly, uh, visited that they mostly, uh, mostly invite them to, uh, just go to our website, just schedule a demo. They'll be, uh, get a designated, uh, solution architect to review and explore everything. They'll have a demo as much as, you know, as much as they want to ask, they'll get answers.
And that's it. I love it. Hey man, I want to thank you for coming on here today and, and making us a little bit smarter, I hope, around secrets and secret management.
Sure. Anytime with some vault list continued success. Exactly.
Yeah. Thank you so much, Alan, for having me, and uh, have a great weekend. Pleasure man.
Alright, all enjoy a key list. Take care. Oh, did Har Har Harve here.
Har. You got it. Har get it eventually.
Yeah. Thank you. All right, we're gonna take a break on Textron.
We'll be right back.