Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Knox serves as a secret management platform designed for the secure storage and rotation of sensitive information such as secrets, keys, and passwords utilized by various services. Within Pinterest, a multitude of keys and secrets are employed for diverse functions, including signing cookies, encrypting sensitive data, securing the network through TLS, accessing AWS machines, and facilitating communication with third-party services, among others. The risk of these keys being compromised posed significant challenges, as the process of rotation typically required a deployment and often necessitated changes to the codebase. Previously, keys and secrets at Pinterest were stored in Git repositories, leading to their replication across the company's infrastructure and presence on numerous employee laptops, which made tracking access and auditing who had permission to use these keys virtually impossible. To address these issues, Knox was developed with the intention of simplifying the process for developers to securely access and utilize confidential secrets, keys, and credentials. It also ensures the confidentiality of these sensitive elements while providing robust mechanisms for key rotation in the event of a security breach, thereby enhancing overall security practices. By implementing Knox, Pinterest aims to streamline secret management processes while fortifying its defenses against potential vulnerabilities.
Description
Address team frustrations related to password management by allowing access to a centralized password pool through a dedicated Slack group. Ensure that all team passwords are securely encrypted and stored in a protected environment, thus reducing the chances of passwords being compromised by existing in multiple insecure locations. We provide a comprehensive documentation of the encryption design and make the complete source code available for public review, enabling thorough code assessments and verification of the zero-knowledge protocol in place. To generate a link for the editor to create a secret, note that this link will expire after 15 minutes. Additionally, to ensure the secret becomes inaccessible, it is essential to manually delete it from the S3 password storage. The setup process for the password storage requires only a single execution, streamlining the implementation. For those looking to obtain a one-time-use link to access secret content, remember that this link also expires in 15 minutes. For detailed instructions on establishing your own password server, visit our GitHub project, and feel free to test commands on your Slack team using our designated test server to familiarize yourself with the functionality. This approach not only enhances security but also fosters a more efficient way to manage sensitive information within teams.
API Access
Has API
Yes
API Access
Has API
No
Integrations
Docker
Yes
Pinterest
Yes
Pradeo
Yes
Slack
No
Swarm
Yes
Yaguara
Yes
Integrations
Docker
No
Pinterest
No
Pradeo
No
Slack
Yes
Swarm
No
Yaguara
No
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Founded
2009
Country
United States
Website
github.com/pinterest/knox
Vendor Details
Company Name
Talpor
Founded
2018
Website
scale.talpor.com
Product Features
Privileged Access Management
Application Access Control
No
Behavioral Analytics
No
Credential Management
No
Endpoint Management
No
For MSPs
No
Granular Access Controls
No
Least Privilege
No
Multifactor Authentication
No
Password Management
No
Policy Management
No
Remote Access Management
No
Threat Intelligence
No
User Activity Monitoring
No
Product Features
Password Management
Credential Management
No
Multifactor Authentication
No
Password Generator
No
Password Reset
No
Password Synchronization
No
Single Sign On
No
User Management
No