1 of 83

Generic Presentation

Solving Secrets Sprawl Takes More Than Security: Why Machine Identity Is Everyone's Problem

https://tinyurl.com/btc-dwayne-secrets

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

2 of 83

🕺 vs 🤖

Human

Non-human

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

3 of 83

Production software environments are composed of a large number of applications which need to be identified, resulting in “non-human identities” or NHI.

Application identities are often associated with secrets, which are used as credentials similarly to the way humans authenticate into computer systems. Application secrets may be used to authenticate into other applications within the trust domain. They may also be used to authenticate into 3rd party SaaS applications.

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

4 of 83

🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖 : 🕺

In 2022…

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

5 of 83

🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖 : 🕺

Now??

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

6 of 83

🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖 : 🕺

Soon…

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

7 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

8 of 83

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

COMPANY�LOGO

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

9 of 83

Hi. I’m Dwayne.

{

Hometown” : “Chicago”,

  • Mission” : “Help people figure stuff out”,
  • Developer-advocate-since : 2014”,
  • Host : The Security Repo Podcast”,
  • Socials : {

mcdwayne@mastodon.social”,

www.linkedin.com/in/dwaynemcdaniel” },

Other-interests: {“crochet”, “karaoke”, “rock and roll concerts”, “music in general”}

}

Dwayne McDaniel�Senior Developer Advocate

At GitGuardian�dwayne.mcdaniel@gitguardian.com

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

10 of 83

🕺 vs 🤖

Human

Non-human

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

11 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

12 of 83

What are secrets in software development?

Definition

Secrets authenticate access and encryption of software components, such as: �

  • API keys
  • Username/password pairs
  • Database connection URLs
  • Browser session tokens
  • Certificates

Sensitive files such as .env, .pem or .crt are also secrets themselves

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

13 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

14 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

15 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

16 of 83

https://www.gitguardian.com/state-of-secrets-sprawl-report-2025

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

17 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

18 of 83

https://www.gitguardian.com/state-of-secrets-sprawl-report-2025

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

19 of 83

What do we do then?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

20 of 83

Don’t Forget To Breathe

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

21 of 83

Train devs to use the tools and follow the processes

People

Tools

Automate detection and remediation

Use vaults, secrets managers and HMS to manage secrets

Processes

Document the steps to follow for incident remediation by devs

Create clear processes for provisioning, manaaging, and rotating secrets

Raise awareness around secrets sprawl and secure coding practices

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

22 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

23 of 83

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

Who “owns” NHIs?

� Who owns the risks?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

24 of 83

Risks are NOT threats.

Risks are NOT vulns.

Risks are NOT exploits.

�Risks are what you are set to lose

if things go bad.

Walt Powell - Field CISO, CDW

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

25 of 83

A Formula For Measuring Security Risk

Security Risk = Threat ❎ Exploitability ❎ Criticality

  • Where am I vulnerable?�
  • What is the likelihood of �a successful attack?�
  • What would it cost the �company or you?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

26 of 83

Business Risks != Security Risks

"The Board does not know or care what a CVE is.�They care that something is going to make them lose money.

�Period."��– again, thank you to Walt Powell - Field CISO, CDW

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

27 of 83

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

28 of 83

Who implements NHIs?

Devs?

DevOps?�Operations?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

29 of 83

Who implements NHIs?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

30 of 83

Who pays for NHIs?

DevOps?�Operations?

Exec Team?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

31 of 83

Breaches cost money.

= risk calculation involving probability�

VS�

Vaults cost money

And Redundancy costs money.

Poor secrets management means we have redundant vaults.

How much money are we losing not addressing this issue?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

32 of 83

Who gets fired in an NHI incident?

Security?�CISO?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

33 of 83

Why not the IAM owner?

Why do we treat Non-Human Identities different than humans?��Does this person even exist in your org?��

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

34 of 83

Solving NHI Security Requires Getting Buy In Across All Teams

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

35 of 83

What do we do then?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

36 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

37 of 83

Eliminate long-lived overprivileged credentials

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

38 of 83

Governance

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

39 of 83

Three pillars of a governance

Train devs to use the tools and follow the processes

People

Tools

Automate detection and remediation

Use vaults, secrets managers and HMS to manage secrets

Processes

Document the steps to follow for incident remediation by devs

Create clear processes for provisioning, manaaging, and rotating secrets

Raise awareness around secrets sprawl and secure coding practices

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

40 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

41 of 83

This is not a talk about “Shadow IT”

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

42 of 83

How do we get Devs/DevOps to stop using long lived credentials?

Devs

DevOps

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

43 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

44 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

45 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

46 of 83

https://spiffe.io/book/

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

47 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

48 of 83

https://datatracker.ietf.org/doc/draft-ietf-wimse-arch/

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

49 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

50 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

51 of 83

Near term vs Long term

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

52 of 83

Eliminate long-lived overprivileged credentials

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

53 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

54 of 83

1x🤖 = 1x🤫

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

55 of 83

Our game plan:

  • Find All The Secrets
  • Properly Store The Secrets
  • Adopt Better Developer Tooling
  • Continual Secrets Scanning
  • Automatic Rotation At Scale

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

56 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

57 of 83

Credentials can appear in plaintext in:�

  • Code
  • Config files
  • Jira
  • Slack/Teams
  • Confluence
  • ~/secrets.txt
  • Other terrifying places

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

58 of 83

trufflesecurity/trufflehog

`git grep -E <pattern>`

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

59 of 83

Our game plan:

  • Find All The Secrets
  • Properly Store The Secrets
  • Adopt Better Developer Tooling
  • Continual Secrets Scanning
  • Automatic Rotation At Scale

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

60 of 83

Basic Secret Manager Architecture

DATA

Secrets Manager

Cloud Services

API Endpoints

Your application

Developer

Logic and APIs

@mcdwayne

@mcdwayne

61 of 83

Are you “all in” on one Cloud provider?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

62 of 83

Multicloud, Or On Prem, Or A Mix?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

63 of 83

@mcdwayne

@mcdwayne

64 of 83

Our game plan:

  • Find All The Secrets
  • Properly Store The Secrets
  • Adopt Better Developer Tooling
  • Continual Secrets Scanning
  • Automatic Rotation At Scale

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

65 of 83

And how do we get Devs/DevOps to use it?

Devs

DevOps

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

66 of 83

Security Engineering

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

67 of 83

Security Engineering

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

68 of 83

Security Engineering

https://github.com/conjurdemos/cyberark-gitguardian-hmsl-remediation-integration-service

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

69 of 83

Our game plan:

  • Find All The Secrets
  • Properly Store The Secrets
  • Adopt Better Developer Tooling
  • Continual Secrets Scanning
  • Automatic Rotation At Scale

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

70 of 83

Are you all in on one Cloud provider?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

71 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

72 of 83

Can you rotate the secret

through an API/CLI call?

Multicloud, Or On Prem, Or A Mix?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

73 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

74 of 83

Who gets fired in an NHI breach?

Security?�CISO?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

75 of 83

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

Who “owns” NHIs?� Who owns the risks?

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

76 of 83

Devs

DevOps/�Operations

Security/�CISO

Exec Team

IAM/Identity

COMPANY�LOGO

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

77 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

78 of 83

🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖🤖 : 🕺

Soon…

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

79 of 83

Train devs to use the tools and follow the processes

People

Tools

Automate detection and remediation

Use vaults, secrets managers and HMS to manage secrets

Processes

Document the steps to follow for incident remediation by devs

Create clear processes for provisioning, manaaging, and rotating secrets

Raise awareness around secrets sprawl and secure coding practices

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

80 of 83

Hi. I’m Dwayne.

{

Hometown” : “Chicago”,

  • Mission” : “Help people figure stuff out”,
  • Developer-advocate-since : 2014”,
  • Host : The Security Repo Podcast”,
  • Socials : {

mcdwayne@mastodon.social”,

www.linkedin.com/in/dwaynemcdaniel” },

Other-interests: {“crochet”, “karaoke”, “rock and roll concerts”, “music in general”}

}

Dwayne McDaniel�Senior Developer Advocate

At GitGuardian�dwayne.mcdaniel@gitguardian.com

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

81 of 83

About GitGuardian

GitGuardian is an enterprise platform helping teams solve Non-Human Identity security crisis

  • Secrets Detection and Remediation Platform
  • Developer Tooling for Prevention
  • Honeytokens
  • Public Monitoring of GitHub

gitguardian.com/state-of-secrets-sprawl-report-2025

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

82 of 83

Generic Presentation

Solving Secrets Sprawl Takes More Than Security: Why Machine Identity Is Everyone's Problem

https://tinyurl.com/btc-dwayne-secrets

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social

83 of 83

@mdwayne-real.bsky.social

@mdwayne-real.bsky.social