People might think that Vault is insecure because if someone compromises the Vault server, they should be able to read any secret. This isn’t true since you need to authenticate to Vault to be able to read secrets. Vault also uses an algorithm known as Shamir’s Secret Sharing to split the master key into shards. This means that even if you hold a key, you aren’t able to unseal Vault unless you have all of them. This is similar [...]

