4 ms·
Note that dumping the Vault's process memory is beyond hashicorp/Vault's threat model. See: https://github.com/hashicorp/vault/issues/1446#issuecomment-22162592
by komuW 4y ago
Note that dumping the Vault's process memory is beyond hashicorp/Vault's threat model. See: https://github.com/hashicorp/vault/issues/1446#issuecomment-221625921 https://github.com/hashicorp/vault/issues/1446#issuecomment-...
I'm bringing this up because the circleCI blogpost says that the attacker did memory-dump encryption keys from a running process. See https://circleci.com/blog/jan-4-2023-incident-report/ https://circleci.com/blog/jan-4-2023-incident-report/
So even if they were using hashicorp/vault, the attacker could probably still have been able to mem-dump vault's process.
- robszumski 4y agoYou can run Vault inside of an enclave to protect it's memory: https://edgebit.io/enclaver/docs/0.x/guide-vault/ https://edgebit.io/enclaver/docs/0.x/guide-vault/