3 ms·
How do you handle a situation where the attacker gains access to decrypted set of secrets and steals them? Can you prevent this scenario in any way, or does sin
by tener 5y ago
How do you handle a situation where the attacker gains access to decrypted set of secrets and steals them? Can you prevent this scenario in any way, or does single hacked admin results in a complete compromise with no way to recover?
- danenania 5y agoIf an attacker gains access to your app's process where the secrets are in RAM, there's not much protection we can offer, since ultimately the variables need to live in plaintext somewhere in order to be used. But recovering is a lot easier/faster since you can track down exactly what was exposed with audit logs and rotate compromised credentials in one place instead of needing to track them down across many devices/servers. For a human user, there are multiple layers of security: email/SSO authentication, a per-device encryption key (stored in the OS credential store on Mac/Windows), and, optionally: a passphrase that locks the per-device encryption key and a lockout that clears RAM and locks EnvKey on the device after a specified time period until the user inputs their passphrase. EnvKey organization owners can require that passphrases/lockouts be set for all org members.