2 ms·
> If you left the private key in a file that is right next to your encrypted configuration file, then it remains as I stated previously: No security except fals
by tstack 12y ago
> If you left the private key in a file that is right next to your encrypted configuration file, then it remains as I stated previously: No security except false security.
Shut up and read the goal of the project already. It is trying to protect secrets that are stored in a repo and it achieves that goal.
Secrets on a deployed host will always be in the clear on that host, it's just a fact of life. Many barriers can be put in place, but at the end of the day, a program will always need access to the plaintext version of the secret at some point.
> It is sensible to type it in while the system is still in single-user mode.
No it isn't. Services have to restart all the time, saying that a human has to be ready to type in a password at any moment is not practical.
> This is not the forum for an education on programming.
But it is a forum for you to post invalid criticisms of a project and act like a dick? That's bullshit. This is "hacker news", it's a perfectly fine place for a technical discussion. If you thought there were problems with the project and this wasn't the right place to discuss it, then file issues on the github project.
> A library that states it was written as a learning exercise with a request for criticism will be treated that way. A library proposed to solve problems recognised in the linked article will not.
There is no difference, you're just trying to justify your bad behavior.