4 ms·
Fair point. Though I feel like in any modern app deployment scenario that isn't going to be a meaningful defensible boundary. The answer is to use neither, es
by photon12 6y ago
Fair point.
Though I feel like in any modern app deployment scenario that isn't going to be a meaningful defensible boundary.
The answer is to use neither, especially given the number of times I've used a path traversal vulnerability to expose /proc/self/environ on a pentest, and the one time I was frustrated on a pentest when every app in the environment used a dedicated API for secret retrieval and the path traversal vulnerability I had access to was worthless.
- imtringued 6y agoHow do docker secrets solve the problem then? According to the article they store the secret in a file as well. You could access the docker secret just as easily as environment variables. The only meaningful difference is that /proc/self/environ will return all secrets at once meanwhile with docker secrets you have to know the file path.
- photon12 6y agoThey don't There's a lot of bad advice on secret storage that is Not Based On A Threat Model™