3 ms·
The section on security is just... bonkers. First it starts by talking about how ZeroMQ security is an "afterthought", linking to an article that should hopefu
by bascule 11y ago
The section on security is just... bonkers.
First it starts by talking about how ZeroMQ security is an "afterthought", linking to an article that should hopefully convince even people with casual security backgrounds this isn't the case: http://hintjens.com/blog:48 http://hintjens.com/blog:48
For what it's worth: ZeroMQ implements the closest thing to a real-world implementation of Dan Bernstein's CurveCP protocol, with a few design flaws fixed, and also a certificate form that allows a limited hierarchical PKI. Normally I'd say using anything other than TLS is a huge warning sign, but as far as non-TLS protocols go, ZeroMQ's "CurveZMQ" protocol actually ends up looking fairly good in my book.
Iris does none of this, advocating the use of global PSKs. Global PSKs are the bane of security professionals everywhere, as they make any system that shares the PSK the weakest link, greatly increasing the chance that the most overlooked system will become a vector for total system compromise. This is why we've generally seen a move away from such systems to running internal PKIs with unique keys per host.
Instead, they claim:
"This is achieved through the observation that if a node of a service is compromised, the whole system is considered undermined."
This is pretty much the opposite trend of modern crypto practitioners.
It's been awhile since I actually looked at their crypto, but at a cursory glance-over again it's hand-rolled and uses bignums without random blinding, greatly increasing the chances of timing side-channels.
If you care about security, you probably shouldn't be using this.