3 ms·
https://cloud.google.com/docs/security/binary-authorization-for-borg https://cloud.google.com/docs/security/binary-authorization-... is one example
by bowmessage 2y ago
https://cloud.google.com/docs/security/binary-authorization-for-borg https://cloud.google.com/docs/security/binary-authorization-... is one example
- threeseed 2y agoApple's system goes further by having incoming requests choose and verify a server and then encrypt itself using the public key of the node to prevent MITM attacks. And a one-time credential to prevent replay attacks. As well as minor things like obfuscating IP addresses, metadata etc.
- aaomidi 2y agoApples system is also the entire pipeline. Borg SREs can still change behavior here. It’s a lot better than what most places have but does not go far enough.
- sodality2 2y agoNone for consumer-facing products, though