Slide 1

Slide 1 text

  Try English LT! for engineers 第10回 2024.03.18 WaTTson

Slide 2

Slide 2 text

2

Slide 3

Slide 3 text

3 Rookie @senpai plz help me! I'm stuck at this step.... screenshot.png ▼

Slide 4

Slide 4 text

4 Rookie @senpai plz help me! I'm stuck at this step.... screenshot.png ▼ Senpai Oh, be careful! Your personal access token is visible in the screenshot 😱 secret:wJalrXUtnFEMI/K7MDEN G/bPxRfiCYEXAMPLEKEY

Slide 5

Slide 5 text

5 Senpai I dedicate this song for you: "Do not Post Credentials on Slack" High School Song ▼ YouTube

Slide 6

Slide 6 text

  "Do not post credentials on Slack" High School Song 2024.03.18

Slide 7

Slide 7 text

  7 2022.4 joined freee K.K. PSIRT: product security incident responce team WaTTson PSIRT Takeshi Tokunaga プロフィール画像の トリミング⽅法

Slide 8

Slide 8 text

8 freee K.K. Empower Small Businesses to Take Center Stage accounting HR Tax filing Founding Workload management Smart ordening

Slide 9

Slide 9 text

9 Information assets accounting HR ● financial information ● accounting journal ● bank account information ● credit card statement ● employee personal information ● attendance ● payroll information

Slide 10

Slide 10 text

10 Protect information assets: trust boundary S A × × trust boundary ● not allow information to go outside the boundary ● strictly control access to the information ✓ ✓ × ✓

Slide 11

Slide 11 text

11 Credential information ● user id ● secret id ● password ● client token ● access token ● secret token ● access key ● private key etc.... Credential information must be treated as securely as the information assets which you can access with it user id ********** LOGIN

Slide 12

Slide 12 text

12 Rookie @senpai plz help me! I'm stuck at this step.... screenshot.png ▼ Senpai Oh, be careful! Your personal access token is visible in the screenshot 😱 # public_channel secret:wJalrXUtnFEMI/K7MDEN G/bPxRfiCYEXAMPLEKEY

Slide 13

Slide 13 text

13 Systematically treat secret informations password managers Multi-Factor Authentication **********

Slide 14

Slide 14 text

14 So, what should we do?

Slide 15

Slide 15 text

15 "Do not post credentials on Slack" High School Song

Slide 16

Slide 16 text

16 https://developers.freee.co.jp/entry/credential-high-school-song

Slide 17

Slide 17 text

17 ◀ featured in ITmedia news answer song by GitHub Japan ▶

Slide 18

Slide 18 text

Appendix

Slide 19

Slide 19 text

19

Slide 20

Slide 20 text

スモールビジネスを、世界の主役に。