3 ms·
> but that sounds quite literally as "skill issue". Not in you personally, but in the environment you work in. You have no idea the environment they work in. T
by ecb_penguin 1y ago
> but that sounds quite literally as "skill issue". Not in you personally, but in the environment you work in.
You have no idea the environment they work in. The "skill issue" here is you thinking your basic knowledge of Vault matters.
> Software like Vault from hashicorp (it's FIPS compliant, too: https://developer.hashicorp.com/vault/docs/enterprise/fips https://developer.hashicorp.com/vault/docs/enterprise/fips) let you create a cryptographically-strong CA and build the automation you need.
They didn't tell you their needs, but you're convinced this vendor product solves it.
Are you a non-technical CTO by chance?
> there are equivalents for mac os and gnu/linux i guess
You guess? I'm sensing a skill issue. Why would you say it's solved for their environment, "I guess??"
> Quite the contrary: it means that the process is technically so trivial the masses can do it in an afternoon and live off it for years with little to no maintenance.
I'm sensing you work in a low skill environment if you think "home lab trivial" translates to enterprise and defense.
> Hence, if a large organization is not able to implement that, the issue is in the organization, not in the technology.
Absolutely meaningless statement.
- znpy 1y ago> You have no idea the environment they work in. The "skill issue" here is you thinking your basic knowledge of Vault matters. I've deployed Vault both at home and in two different companies, doing anything from pki, mutual-tls, secret storage and other stuff. > > Software like Vault from hashicorp (it's FIPS compliant, too: https://developer.hashicorp.com/vault/docs/enterprise/fips https://developer.hashicorp.com/vault/docs/enterprise/fips) let you create a cryptographically-strong CA and build the automation you need. > They didn't tell you their needs, but you're convinced this vendor product solves it. It was an example from the ecosystem of available tools but in general yes, Vault can do that. Mentioning FIPS compliance was about letting you know that the software can be used also in governative environments. It's not just a "homelab toy". > Are you a non-technical CTO by chance? Senior cloud engineer here. Worked anywhere from not-so-small companies (250 people, 100 engineers) to faangs (tens of thousands of engineers). > > there are equivalents for mac os and gnu/linux i guess > You guess? I'm sensing a skill issue. You're attacking me on a personal level because you can't argue otherwise. That's a common logical fallacy ("Ad Hominem" - https://www.britannica.com/topic/ad-hominem https://www.britannica.com/topic/ad-hominem). You basically have skill issue at debating =) > Why would you say it's solved for their environment, "I guess??" When you account Windows, Mac OS and Linux you're accounting for pretty much the totality of the desktop computing landscape. The last two macbooks I had for work came with the mac os equivalent of group policies with certificates installed etc etc. Enterprise-tier Linux distributions can do that as well (eg: Red Hat Enterprise Linux). > I'm sensing you work in a low skill environment if you think "home lab trivial" translates to enterprise and defense. Again, worked anywhere from companies with 250 people to FAANGs. You have skill issue at sensing, it seems. To get back to the point: homelab "triviality". In a way, yes. Large enterprises and even more defense can spend all the money not just for software but even for consulting from various company that can bring the skills to implement and maintain all the services that are needed, and train your people at that. Things become non trivial not on the base of technical issue, but on the base of organizational issues... If we talk government and defense... Do you know the US government has dedicated cloud regions (eg: https://aws.amazon.com/govcloud-us/ https://aws.amazon.com/govcloud-us/)? Do you really think that cloud providers offer those services at loss? Do you really think a few vault enterprise licenses are the issue there? And by the way, Vault is just an example of one of the possible solutions. It was meant to be an example but you clearly missed the point. > > Hence, if a large organization is not able to implement that, the issue is in the organization, not in the technology. > Absolutely meaningless statement. I think it's very meaningful. It's not 1995, cryptography isn't arcane anymore. We had hardware crypto acceleration in cpu since at least 2010 (AES-NI). The tooling is well established on both servers and clients. The skills are on the market ready to be hired (either via employment or via contracting). The issue is not technical in nature. Oh and by the way: I've worked closely with engineers working for the US government. I wasn't close to the US government (because I am not an US citizen) but they were. They were "close enough" that they had to work in a SCIF and could only interact with me via phone. The systems they were working on... Those systems had their own private CA (among other things). It's feasible. It's not a technical issue. If it's not done then it's an organizational issue.
- ecb_penguin 1y ago> It's not 1995, cryptography isn't arcane anymore. My username is literally a cryptographic mode of operation. But you didn't know that, because you have a low skill issue. > Do you know the US government has dedicated cloud regions (eg: This is a joke, right? You're just an LLM going through training.
- znpy 1y ago> My username is literally a cryptographic mode of operation. But you didn't know that, because you have a low skill issue. Again, ad hominem attack... You proved yourself to be quite a fool. You can't argue, you can't back your own opinions, you are only capable of attacking on a personal level. > This is a joke, right? You're just an LLM going through training. My account is from 2015 and has ~11k points. Your account is 4 months old and barely has 150 points. It's more likely that you're a poorly trained LLM (whoever trained you had skill issues :P) rather than me. I'll be dropping this useless conversation. Farewell.
- ecb_penguin 1y ago> Again, ad hominem attack That's not what ad hominem means. Ad hominem doesn't mean I can't insult you > My account is from 2015 and has ~11k points. Your account is 4 months old and barely has 150 points. It's more likely that you're a poorly trained LLM (whoever trained you had skill issues :P) rather than me. Content matters more than age you goofball
- rfl890 1y agoRelax, dude. https://xkcd.com/386/ https://xkcd.com/386/
- ecb_penguin 1y agoI don't know why you think a couple sentence reply is all that difficult...
- stego-tech 1y agoInterjecting into this back-and-forth real quick. * Yes, I have experience with Vault. I have deployed it internally, used it, loathed it, and shelved it. It’s entirely too cumbersome for basic PKI and secrets management in non-programmatic environments, which is the bulk of enterprise and business IT in my experience. * You’re right, the organization is the problem. Let me just take that enlightened statement to my leadership and get my ass fired for insubordination, again, because I have literally tried this before with that outcome. Just because I know better doesn’t mean the org has to respect that knowledge or expertise. Meritocracies aren’t real. * The reason I don’t solve my own PKI issues with Caddy in my homelab is because that’s an irrelevant skill to my actual day job, which - see the point above - doesn’t actually respect the skills and knowledge of the engineers doing the work, only the opinions of the C-suite and whatever Gartner report they’re foisting upon the board. Hence why we have outdated equipment on outdated technologies that don’t meet modern guidelines, which is most enterprises today. Outside of the tech world, you’re dealing with comparable dinosaurs (no relation) who see neither the value or the need for such slick, simplified solutions, especially when they prevent politicians inside the org from pulling crap. I’ve been in these trenches for fifteen years. I’ve worked in small businesses, MSPs, school campuses, non-profits, major enterprises, manufacturing concerns, and a household name on par with FAANG. Nobody had this solved, anywhere, except for the non-profit and a software company that both went all-in on AD CA early-on and threw anything that couldn’t use a cert from there off the network. This is why I storm into the comments on blogs like these to champion their cause. PKI sucks ass, and I’m tired of letting DevOps people claim otherwise because of Let’s Encrypt and ACME.