4 ms·
Show HN: Encrypt your home-lab server disks using AWS Key Management Service
- oconnore 9y agoThe only confusing thing about this is: you’re cool with AWS but insist on deploying your own hardware for personal projects! You can buy a lot of EC2 compute per month before you hit the cost of running outdated servers on your power bill.
- subway 9y agoDepends on what you're doing. It's still way cheaper to host block storage at home than most any cloud provider right now.
- randomv 9y agoYeah, that's a pretty big deal. Costs add up quickly on S3 even with Glacier. But I agree, often AWS is better for your lab than a home server, particularly if what you need to test is clustering. Also, Elastic Filestore over a VPN connection is not a particularly great experience ;)
- evook 9y agoExcept if you need and use a lot of storage.
- TheDong 9y agoAbsolutely not true. You can buy a 1u server with 2 processors / 24 logical cores and 32 gigs of ram off ebay for around $150. Say what you have is 2x L5640 Xeons (pretty common, again on ebay). You'll be drawing 80-150W depending on load per cpu. Let's say it's on the upper end and you draw about 250W. Average electric costs in the US are 12c/kwh. That means those cores will cost around $20/month. In reality, other things draw power, but your average usage will be lower, so $20/month for 32GB of ram and 24 kinda crappy cores is about right power wise. Look at AWS's pricing and tell me I can get anything even approaching that at such a good price point.
- e_d_e_v 9y agoCame here to say this. Load up on $20 2TB SAS drives in an R510 or something like that, and you'll use a little more power, but also be beating the pants off AWS for cost/GB purposes.
- lamlam 9y agoWait, where can you purchase 2 TB drives at $20 USD?
- martin_andrino 9y agoComparing raw hardware with one of the dozens of services offered by AWS is absurd to say at least, as you’re basically ignoring the whole platform that enhances “EC2” - of course raw hardware price will always win, but that doesn’t really mean anything as the comparison isn’t a good one.
- ganoushoreilly 9y agoAs a base problem of "I need fast storage and CPU resources" isn't necessarily solved in the cloud either. If you're deploying hardware that needs to write large amounts of data daily and requires high CPU availability, even if AWS pricing was ok, you're still connectivity bound, which itself is an increased cost. I can also see this being valuable for MSSP's deploying assets across client networks and wanting to manage encryption keys in the cloud, vs on prem. None of the additional Amazon cloud features are even in play with the above scenario.
- deleted 9y ago[deleted]
- TheDong 9y agoYes, I agree that it's a dumb comparison. I'm only making it to refute the parent comment which said: > You can buy a lot of EC2 compute per month before you hit the cost of running outdated servers on your power bill. I can't see any way of interpreting that other than as them claiming the dumb comparison I just made plays out differently than it does. If the parent comment said something like "It will take a lot of time and money to reproduce any meaningful percentage of what EC2 offers" I'd be in agreement... but the parent comment was directly comparing a power bill with ec2 compute costs.
- Johnny555 9y agoI have a 45W 9TB fileserver at home (5x3TB disks, RAID-6), which costs me around $5/month in electricity. Plus another $10 for the Crashplan backup. I'm using around 3TB of space on it currently, which would cost around $70/month in S3 or $12/month in Glacier (in reality I'd use a combination of S3/Glacier so my costs would be somewhere between $12 and $70/month) Granted, the hardware costs me around $25/month amortized over 3 years but my internet speed isn't fast enough (or unlimited enough) to let cloud storage be a viable replacement of a local fileserver.
- oconnore 9y agoOk, so you're at 25/mo + 5/mo + 10/mo = $40/mo for self hosted. That's almost exactly "halfway between 12 and 70/mo". Plus, S3/Glacier and a backed up hard drive (even with raid) are nowhere near the same product.
- Johnny555 9y agoBut like I said, my internet bandwidth + quota is not high enough to replace my fileserver with cloud hosting, so I'd still have that expense -- and the $25/month fileserver also acts as a security camera recorder, a media server and a few other things, so it's more than a fileserver. And yeah, S3 is not a fileserver replacement,AWS's best solution for that would be EFS, but that'd cost me $900/month for my usage.
- Tepix 9y agoBizarre.
- deleted 9y ago[deleted]
- TheDong 9y agoThreat-model wise, this seems no different from storing the decryption secret on disk (wherever the access/secret keys are stored in this setup), with one exception: remotely-revokable keys. That is a nice property and a pretty cool way to achieve it.
- randomv 9y agoThere's a few different revocation options: * `grant-computer` creates a KMS grant as per http://docs.aws.amazon.com/kms/latest/developerguide/grants.html http://docs.aws.amazon.com/kms/latest/developerguide/grants.... . `revoke-computer` removes the grant without touching the keys. * The AWS access keys for the IAM user the tool uses, which can be rotated, revoked, recreated, etc... * The per-disk encryption key, which can be deleted from DynamoDB * The KMS CMK, which can be deleted, disabled, etc... I mainly wanted to solve having to plug in a keyboard and type something in, or having a key on a USB stick and be diligent enough to take it out of the home.
- justinjlynn 9y agoOnce secret data, especially potentially valuable but small data, is shared beyond one's own control, never assume it can be or has been deleted. In fact, one should probably assume the opposite. Has it been saved? Probably not, but it could easily be. Carefully evaluate your threat model, the risk might be small enough to be acceptable, but always exercise great care in saying "but it can be/has been forgotten".
- click170 9y agoThis is really cool and reminds me a bit of Mandos which does full disk encryption on headless servers using a network host. The Readme didn't mention, can this be configured to SMS me when an encryption key is handed out?
- randomv 9y agoIt uses the GenerateDataKey API against a single master key. At the client side, yes, could send an SNS notification, or otherwise go indirectly via a Lambda. Or, alternatively, stream CloudTrail logs through Lambda to achieve a similar result.
- QuinnyPig 9y agoYou can have an SNS topic configured to message you on a key creation event via Lambda worst case. We’re talking maybe seven lines of code here.
- mlosapio 9y agoBecause that’s exactly what I want to do - give my home encryption keys to amazon.
- aruggirello 9y agoYep, and the keys could be renewed or revoked remotely. What could go wrong?
- wjd2030 9y agoSometimes I read about projects like this and just think to myself "Your scientists were so preoccupied with whether or not they could, they didn’t stop to think if they should."
- advisedwang 9y agoMy understanding is the machine needs AWS credentials to use this. So instead of managing disk encryption keys, you have to manage AWS credentials instead. Can somebody correct me if this is wrong? If this is the case, then this is really only useful for managing multiple disks and giving some remote control.
- Kamshak 9y agoQuite nice since you can very easily manage aws credentials and get stuff like 2FA. Encryption Keys might be a bit trickier.
- deleted 9y ago[deleted]
- mooreds 9y agoWhat happens if you need to decrypt a disk and you are not online? It wasn't clear to me that you'd have access to your data. Maybe that is OK, maybe not.