4 ms·
I totally tuned out that this is a Cloudflare repo. Some Googling turned up a USENIX slide deck that puts this into context: https://www.usenix.org/sites/defa
by SloopJon 4y ago
I totally tuned out that this is a Cloudflare repo. Some Googling turned up a USENIX slide deck that puts this into context:
https://www.usenix.org/sites/default/files/conference/protected-files/srecon17asia_slides_korchagin.pdf https://www.usenix.org/sites/default/files/conference/protec...
Whereas the README uses URLs as the realm string, the slides uses realm strings like "root-password" or "ssh-v2" to derive keys from a seed stored in a UEFI variable.
I think the idea is that you can administer all of your servers with one master password, while each server derives different passwords locally from its own seed. If a given seed is compromised, rederive the passwords from a new seed (or reprovision the server from scratch). If your master password is compromised ... well, try not to let that happen.
- e12e 4y ago> If your master password is compromised ... well, try not to let that happen. Good thing that keyloggers don't exist then... :'(