BSides Toronto 2022

Layers of Cloud: Azure and the (Mis-)Storage of Secrets
10-08, 11:30–11:55 (Canada/Eastern), ENG-103

Where are secrets stored in Azure? Is it even safe to put secrets in the cloud to begin with? There's so many services in Azure that this isn't easy to answer. We'll start by taking a look at common ways passwords should be stored, and how these services have grown through patching recent vulnerabilities. Then we'll shift to look at common spots where it looks like passwords should go... but really shouldn't. We'll end with how to ensure your secrets the shared responsibility model, and a quick reflection on the shared responsibility model. Both new & experienced cloud lovers welcome!

Katie Knowles is a cloud security enthusiast with a passion for keeping new technology secure. In her current role, she is a Senior Manager on PwC’s Threat Response team with a focus on all things cloud. Her previous work includes penetration testing Fortune 500 corporations, securing aerospace networks, and helping run a corporate bug bounty program. She has earned OSCP, GPEN, GCSA, AZ-104, and AZ-500 certifications, and holds a BS in Electrical Engineering from RIT.