7 ms·
"If you're not using <thing that my company sells> you're doing it wrong"
by eigenloss 7y ago
"If you're not using <thing that my company sells> you're doing it wrong"
- mmalone 7y agoAuthor. We don’t sell anything related to what’s in that post (actually we don’t sell anything right now). It’s all open source. We believe everyone deserves good PKI; that it’s an underutilized technology with bad tools. We have plans to make money off other stuff once that’s in place.
- otterley 7y agoAlso, "you're doing it wrong" reeks of arrogance, and makes me not to want to do business with you.
- mmalone 7y agoEh, it’s just an attention getter. Marketing and messaging using unequivocal statements works. SSH cert authn is super useful tech that deserves better marketing. Damned if you do, damned if you don’t. Sorry.
- otterley 7y agoPerhaps - but I think it's better to punch up. Strive for excellence, and the attention you want will come.
- mmalone 7y agoSorry but part of making information accessible is communicating using less formal language. I could have titled the post “A comparative analysis of certificate-based authentication relative to other SSH authentication mechanisms”. I am capable of using fancier words too. But no one would have read it. I’d have been preaching to the choir. Perhaps the title could have been more diplomatic. Perhaps I was not sensitive enough to the feelings of folks who use non-certificate-based SSH authentication. But it’s just a title. I meant no harm. <3 Do you have any feedback on the content itself? :)
- prepend 7y agoIt’s not the formality of your language that is creativity negative attention for your org. It’s the hyperbole and inaccuracy. It’s quite possible to be accurate in my language and still speak informally. It bugs me a little that you seem to be deflecting criticism and minimizing it rather than just accepting it and moving on. I didn’t think your headline wasn’t “diplomatic” enough and don’t think that’s relevant to this comment hierarchy where you respond.
- mmalone 7y agoI accept your criticism. Sorry.
- prepend 7y agoThanks. As a big fan of intelligent cert usage we can now get onto more interesting discussion.
- cerberusss 7y agoI think the author is correct in deflecting the criticism here. There's a lot of bashing about headlines and such, and not much on the content itself, which would've been more interesting to me.
- kjaftaedi 7y agoThe amount of people who understand terms like 'grok', but don't know how to use SSH certificates is effectively zero. You need to get to familiarize yourself better with your audience.
- mmalone 7y ago> The amount of people who understand terms like 'grok', but don't know how to use SSH certificates is effectively zero. I don’t want to be antagonistic but that’s just not true. I’ve talked to a lot of people about this. Maybe 10% of people I’ve talked to know how to use ssh certs. These are technical people who are very smart and know what they are doing, and know what “grok” means. That’s why I wrote the post. If you already knew the info in the post then cool! Sorry to waste your time.
- teh_klev 7y agoYou got my attention. I've got ~25 years Unix/Linux experience under my belt and didn't know about SSH certs and now I do. So appreciated.
- mmalone 7y ago<3
- archi42 7y agoSimilar here: Even though I was somewhat aware ssh could do some PKI magic, I didn't CONSIDER deploying it. But I'll try to get our sysadmins to use it. Having U2F/FIDO support seems like THE big bonus to me (also I'd like to replace that ancient HTTP basic auth on our intranet with something more user friendly and add U2F as well). So huge thanks for the article! OTOH, key deployment depends on the situation and size. We have a single office (=> no network bottlenecks), our /home lives on a central NFS and machines pull their users from LDAP. When I joined the company, after I got my account, I ran `ssh-keygen`, set my keyphrase and could connect to any machine. If someone quits, the LDAP user is removed. Regarding TOFU: I think we have some admin.git which contains all machines, and their public keys are distributed from there. So no TOFU for us. With PKI this central repo of machines wouldn't magically go away, the script would be just someone else's/your's (and it would be technically cleaner). Also, when reusing hostnames the deployment system could reuse the sshd keys instead of creating new ones.
- AnIdiotOnTheNet 7y ago> Eh, it’s just an attention getter. Admitting it is clickbait does not lessen my disdain for the use of clickbait.
- eigenloss 7y agoAwesome! Sorry if my comment came across as dismissive.