DOP 230: Simplifying End-to-End Encryption With Smallstep

DOP 230: Simplifying End-to-End Encryption With Smallstep

Source: YouTube · DevOps Paradox · published Sep 27, 2023 · 43:31

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

Scaling engineering productivity requires focusing on how teams develop technology at scale, not just the technology itself 0:00 and 24:35.

Key Takeaways:
• The transition from on-premises "fortress" security to cloud computing created new challenges as organizations moved to distributed systems 4:24 and 22:00
• Microservices primarily enable scaling people processes by enforcing component hygiene rather than just technical benefits 24:35
• Security needs evolved as startups grew and larger organizations adopted rapid development methodologies 22:00
• Modern systems require end-to-end encryption at multiple layers, with encryption becoming more affordable and accessible 29:53 and 31:22
• Small Step provides open source tools (Step CA and Step CLI) making certificate management accessible at scale 35:51

Engineering productivity at scale requires balancing rapid development with proper security practices.

Sources:

  • 0:00 Discussion on scaling engineering productivity
  • 4:24 Evolution from physical data centers to cloud
  • 16:01 OAuth vs OpenID history and differences
  • 31:22 End-to-end encryption in modern systems
  • 35:51 Small step open source tools for certificate management

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

it's about how do we get a thousand Engineers or 10 000 Engineers to work productively together on one effectively like what comes together as one system it's not about technology really at all it's about how you develop technology at scale quickly this is devops paradox episode number two three zero simplifying end-to-end encryption with small step welcome to devops paradox this is a podcast about random stuff in which we Darren and Victor pretend we know what we're talking about most of the time we mask our Ignorance by putting the word devops everywhere we can and mix it with random buzzwords like kubernetes serverless cicd team productivity islands of happiness and other fancy Expressions that make us sound like we know what we're doing occasionally we invite guests who do know somethi…