3 ms·
> It's a bit scary how much I am being downvoted for asking what I believe to be a reasonable question. > On the low end of my concern is the annoyance of cons
by gabeio 3y ago
> It's a bit scary how much I am being downvoted for asking what I believe to be a reasonable question.
> On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets.
> Is there any assurance this won't happen?
This isn’t really a reasonable request. You can do any of this yourself as well, so your assurances are your own. If you want someone else to own those assurances you need to pay up.
- aestetix 3y ago> This isn’t really a reasonable request. You can do any of this yourself as well, so your assurances are your own. If you want someone else to own those assurances you need to pay up. Sure it is. This is what third party security audits exist for. For example: https://www.hashicorp.com/solutions/auditing-and-compliance https://www.hashicorp.com/solutions/auditing-and-compliance This isn't unique to Hashicorp. Any organization which claims to offer secure protection should be willing to share this kind of information. https://docs.securedrop.org/en/stable/what_is_securedrop.html#audits https://docs.securedrop.org/en/stable/what_is_securedrop.htm... https://threatpost.com/openssl-security-audit-ready-to-start/111538/ https://threatpost.com/openssl-security-audit-ready-to-start... The point here is not "we pay more money and get better security." That's the kind of garbage logic the SSL CA cabal used for decades to maintain a monopoly before LetsEncrypt showed up. The question is, what is an indication that, although there is clearly some drama, that I can trust the software with my secrets? Did some of the people come to this new project from the Hashicorp security team? Could it be that the majority of changes in codebase are on the UX/UI, and not the security protocol implementation? There are plenty of ways to publish trust validation without demanding that a potential user spend hours poring through code looking for exploits.