Finding leaked credentials in Docker images - How to secure your Docker images

Описание к видео Finding leaked credentials in Docker images - How to secure your Docker images

Docker can be a blind spot for security, in this video we look at leaked credentials inside docker images. We evaluate how leaked secrets like API keys and certificats are leaked into docker images, how we can detect them and how we can protect our own images.

Resources:
Research into leaked credentials in docker images: https://blog.gitguardian.com/hunting-...
Dive, tool to view docker images: https://github.com/wagoodman/dive
GG-Shield, tool to scan docker images: https://github.com/GitGuardian/ggshield
GitGuardian, Secrets detection solution: https://dashboard.gitguardian.com
Cheatsheet, protecting docker images: https://blog.gitguardian.com/how-to-i...

Intro: 0:00
What are secrets: 0:49
What is docker: 2:10
Inside docker images: 3:24
Examples of leaked secrets: 5:19
How secrets leak in docker images: 7:08
Docker security research: 10:00
Scanning Docker for secrets: 11:40
Wrap-up: 16:41

Комментарии

Информация по комментариям в разработке