4 ms·
Ignorance: What's the use-case for this? If you can't rely on the drives not to be tampered with, surely you also cannot rely on the CPU or kernel? Am I missin
by bArray 4y ago
Ignorance: What's the use-case for this? If you can't rely on the drives not to be tampered with, surely you also cannot rely on the CPU or kernel?
Am I missing something?
- maxbond 4y agoThis stores blobs in S3. So this is about not trusting hard drives which you have rented. Whether or not that makes sense depends on your threat model, but it seems reasonable to me that there are people who would find this useful.
- nine_k 4y agoThe S3 in question may be not on AWS, but on any of the S3-compatible providers, or a non-public S3 store (in your company, university, your friend's NAS which you use as an extra backup, etc).
- nathants 4y agoi think the best way to think of this is that it's cheaper than private github/gitlab and easier that aws codecommit. also other stuff.
- bcjordan 4y agoI feel like once web browsers / hardware devices start to implement authentication the UX and accessibility of these sorts of tools can become a default choice for user data. The hard part is solving the "lost my yubikey" UX issue but I suspect Apple will reach a reasonable solution that finds an OK balance of convenience and user-authenticating security.
- nathants 4y agountrusted hosts open up a bunch of interesting system designs. i’m mostly thinking about these recently. trusted hosts have good use cases, but shouldn’t be used otherwise. trust hard. lost my yubikey is somewhat covered by the popularity of crypto. recommend users to backup fido2 secrets as bip39 mnemonics. ios and android will hopefully help popularize fido2.
- nathants 4y agoeasier than aws