4 ms·
Tom here from Doppler. I'm a founding engineer at Doppler and work on most of our security. Feel free to hit me with any security questions about our product, p
by tompic823 6y ago
Tom here from Doppler. I'm a founding engineer at Doppler and work on most of our security. Feel free to hit me with any security questions about our product, philosophy, etc.
- qchris 6y agoHi, congrats on the launch! Potentially a little off topic, but I'm curious how you came up with the name Doppler. After the audio effect, or the Witcher creature, or something else entirely?
- bvallelunga 6y agoThe domain was available ;) More seriously, outside of the properties (easy to spell and most people have heard of it before) I wanted something that was more than just environment management. Something grand we could grow into.
- quinndiggity 6y agoIt is a re-use/pivot of a name for a previous project from Brian that didn't take off: ``` Show HN: Doppler – Machine learning marketplace of pretrained models (producthunt.com) - 6 points by bvallelunga on Apr 25, 2018 | 1 comment ``` It's a cool name for sure, but after perusing the founder of this project's blog posts and other web activity, their highly misleading marketing ("you have three options: waste time, don't even try, or pay us!" https://doppler.com/blog/build-vs-manual-vs-buy https://doppler.com/blog/build-vs-manual-vs-buy | "we recreated what these specific competitors which are already established made; they sucked, you don't want to use them, take our word for it and pay us instead of looking for yourself!" https://news.ycombinator.com/item?id=24719722 https://news.ycombinator.com/item?id=24719722 ) I question their morals. Substantive criticism: your marketing needs not be slinging mud, and referencing specific established players in your marketing material in order to give false credibility that you are a one-for-one replacement is a shady practice. I looked at your post solely because it contrasted itself from your competitors claiming superiority, and was disappointed by all of the above AND that the fact that it couldn't do the things it claimed to by making those contrasts. All in all, disappointed to see a ycombinator funded project hoisted on HN with all the above going on, and one with a large number of investors behind it and no open source to back up their claims. This isn't just a community built tool to improve developers' lives, this is a marketing push by a corporation with the intent to get a burst of customers with misleading/questionable marketing.
- quinndiggity 6y agoA great example of not trying to play politics/marketing-spin to elbow competitors in the face: https://www.vaultproject.io/docs/vs https://www.vaultproject.io/docs/vs ``` More importantly, just as we like to present information about Vault and its capabilities in the ways that we prefer, we felt it wasn't appropriate to describe the capabilities of other projects or products in ways other than their own terms. ```
- adriaanmulder 6y agoHey Tom! I see in the security section it says "We secure your data at rest through a mechanism called tokenization, which ensures our systems only store references to your secrets. In the event of a data breach, attackers would only gain access to the references." If this is the case, then where are the secrets stored? How can you view the secrets from the web console if they aren't stored anywhere? Thanks!
- tompic823 6y agoGreat question! We tokenize all secrets and then store the tokens in our database. The raw secrets are stored with our tokenization provider, VGS. When you fetch your secrets, either via our dashboard or CLI, we exchange the token for the raw secret value and then relay that value in our response. This ensures that our infrastructure never persists raw secret values. You can find more information about this process in our Security docs [0]. [0] https://docs.doppler.com/docs/security-fact-sheet#data-flow-architecture https://docs.doppler.com/docs/security-fact-sheet#data-flow-...
- adriaanmulder 6y agoThanks for the quick response. I think this should really be explicitly stated in the docs, along with a link to VGS. The diagram didn't make it obvious to me that the "security provider" block is actually storing the secrets, rather than just converting them into tokens.
- tompic823 6y agoThanks for that feedback, I completely agree. I've updated the linked page to mention this more explicitly.