Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Foxboron
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
121.
▲
by
Foxboron
3y ago
I'm very sure you are actually just rebuilding the container images themselves, not the package tree you are depending on. Building reproducible ISOs, or container images, with a package repository as a base isn't particularly har
122.
▲
by
Foxboron
3y ago
> Your comment can be misinterpreted as saying "Nix does not do binary reproducibility very well, just input reproducibility", which is false. It's only "false" as nobody has actually tried to rebuild the entire
123.
▲
Show HN: sbctl – Secure Boot key manager
(github.com)
57 points
by
Foxboron
3y ago
|
3 comments
124.
▲
by
Foxboron
3y ago
There are multiple legit use cases for TPMs, ssh-tpm-agent is neither the first nor the last. Simple key storage and signing is the base useage for these things, people just focus on the "wrong" aspects of this.
125.
▲
by
Foxboron
3y ago
> 1) is there a simple key destroy function? Just rm the key file. TPM sealed secrets are never actually stored inside the TPM, they are just files with strong encrypted that only the TPM can decrypt. So deleting the key file removes you
126.
▲
Store SSH keys inside the TPM: SSH-tpm-agent
(linderud.dev)
3 points
by
Foxboron
3y ago
|
0 comments
127.
▲
by
Foxboron
3y ago
--first-parent is a nice option I wasn't aware of. But it would still depend on upstream not merging PRs failing the test suite.
128.
▲
by
Foxboron
3y ago
No, it does a binary search over the 100 commits. You would probably hit the issue before you hit 7 or 10 commits depending on how lucky you are.
129.
▲
by
Foxboron
3y ago
Bisecting to find the root cause is always going to be a better strategy if you know there is a good version. I really recommend adopting this strategy.
130.
▲
by
Foxboron
3y ago
Right. Imagine you are a terraform provider developer that is working on making sure their code is working with `opentf`. Lets imagine opentf does an initial `v1.0.0` release of their code and your provider doesn't work. But you know
131.
▲
by
Foxboron
3y ago
Most people don't spend this much time on PR before releasing their fork though. If they had worked on this publicly from the start I'm sure a lot of the current PRs would have generally been of better quality as they could get co
132.
▲
by
Foxboron
3y ago
> Branch protection doesn't allow merging without a passing test-suite. https://github.com/opentffoundation/opentf/pull/243 EDIT: and just to point out. If you have 1 PR with 19 commits that break the
133.
▲
by
Foxboron
3y ago
How does the merge setting solve the complete lack of any useful information in the pull request?
134.
▲
by
Foxboron
3y ago
The squash merge is not going to solve the lack of proper commit messages and the fact that things are breaking the test suite left, and right. Figuring out bugs with `git bisect` is not going to be a fun endeavour for people trying to unde
135.
▲
by
Foxboron
3y ago
It would be trivial to at least continue the standards set by the terraform project. Now there are commits messing with `internal/backend` that breaks tests with the commit message "more". Someone is going to hit this wit
136.
▲
by
Foxboron
3y ago
As technical lead for the OpenTF project, how does things like this get merged? https://github.com/opentffoundation/opentf/pull/36/commits
137.
▲
by
Foxboron
3y ago
I've been hacking on `ssh-tpm-agent` which allows you to create or import TPM sealed keys. This is practical as it prevents key extraction and it has dictionary attack protection which allows you to have 4 digit pins instead of passphr
138.
▲
by
Foxboron
3y ago
>additionally, as I understand it, this basically boils down to use-after-free due to unsafe code, which could occur in either agent implementation, even without loading an extra .so, although the presence of .so loading in general certa
139.
▲
by
Foxboron
3y ago
Apparently you can use a ssh-agent for HostKeys, and by extension ssh-keysign. So I think this should be trivial to implement actually. It might be cool to add some attestation feature so you can verify the boot of the machine before releas
140.
▲
by
Foxboron
3y ago
> are you extending this to the usage of yubikey-agent and ssh-tpm-agent as well? No, as they never get loaded into the ssh binary and are external programs communicating over an interface. Consider reading over the recent qualys vulnera
141.
▲
by
Foxboron
3y ago
When you see a guide containing a 7 step manual to do something that should be simple, it's worth taking a step back and consider the question if you can make this valueable security feature more easily accessible. Side-loading so-name
142.
▲
by
Foxboron
3y ago
No, this isn't true nor correct. Secure Boot and TPM do offer tangible security benefits and is security features you can take ownership of. Secure Boot allows your own key hierarchy, and TPM allows you to take ownership. The linked
143.
▲
by
Foxboron
3y ago
>Are you sure about that? Presumably the secret parts of the SSH key are being read into memory at some point, or a RCE could dump the key the same way ssh-tpm-agent does. This is not how ssh-tpm-agent works. It does the key signing insi
144.
▲
by
Foxboron
3y ago
It has 6.3 Kb or something of memory. So not a lot. What `ssh-tpm-agent` does is that it simply doesn't store the keys on the TPM at all. It creates the ephemeral SRK, then load a sealed private key back into the TPM that allows us to
145.
▲
by
Foxboron
3y ago
It's not written in the README.md, but `ssh-tpm-agent` is very much a copy-paste of `yubikey-agent` but with a bit better testing and the yubikey part swapped with TPM stuff.
146.
▲
Show HN: ssh-tpm-agent – SSH agent for TPMs
(github.com)
86 points
by
Foxboron
3y ago
|
38 comments
147.
▲
Store age identities inside the TPM: age-plugin-tpm
(linderud.dev)
3 points
by
Foxboron
3y ago
|
0 comments
148.
▲
by
Foxboron
3y ago
How does Heads and Pureboot solve the Root of Trust issue outlined in the blog post?
149.
▲
by
Foxboron
3y ago
Yes, they are testing this for a fraction of their packages. It still amounts to less testing then what distros like Guix, Debian and Arch Linux is currently doing.
150.
▲
by
Foxboron
3y ago
> reproducible builds fwiw, NixOS does not support reproducible builds as defined by the Reproducible Builds project. They support reproducible environments/configuration/deployments or how you want to describe it.
More ›