3 ms·
vault (https://vaultproject.io https://vaultproject.io) uses Shamir to generate shares for operators to unseal the vault. In the latest release (1.0beta), vault
by ppierald 8y ago
vault (https://vaultproject.io https://vaultproject.io) uses Shamir to generate shares for operators to unseal the vault. In the latest release (1.0beta), vault seal keys can be wrapped with something like AWS KMS which allow for operator-less unsealing of the seal keys, but trade that off with potential operator access to the seal key itself.
Collusion between operators is a real problem of Shamir-based key systems. If you have a crypto system that depends on Shamir keys and a few of your operators leave the organization or become untrustworthy for some reason, then you need to revoke / resplit the origin key data material.
Additionally, the output of the ssss command itself is not secure, so you should consider having that data going through GPG to give each operator a GPG / keybase'd output which has never been seen in cleartext by anyone but themselves.
Long story short, key management continues to be really hard and needs to be thought through from begin to end with operational procedures in place to handle the real life situations that occur (employee collusion, employee join/depart, breach).
- justingood 8y agoI really enjoy that Vault has included the ability to use Keybase to encrypt the initial unseal keys easily: https://www.vaultproject.io/docs/concepts/pgp-gpg-keybase.html https://www.vaultproject.io/docs/concepts/pgp-gpg-keybase.ht...