Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cipherboy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
OpenBAO – Maintainers, Commiters, and Moderators Oh-My
(openbao.org)
2 points
by
cipherboy
2y ago
|
0 comments
32.
▲
Announcing the OpenBao Blog
(openbao.org)
2 points
by
cipherboy
2y ago
|
0 comments
33.
▲
by
cipherboy
2y ago
Which reference AES implementation? My memory is that the one from the spec has terrible timing side channel attacks... e.g. https://www.redhat.com/en/blog/its-all-question-time-aes-tim... seems to corroborate my
34.
▲
by
cipherboy
2y ago
FWIW, most of the code and docs contributions have come from non-IBMers [0]. That said, IBM has done a lot of great work building the foundation and initial community and without them, OpenBao wouldn't be here. :-) Speaking for myself,
35.
▲
by
cipherboy
2y ago
And OpenBao's fork of Vault. There are non-IBM companies on the TSC.
36.
▲
by
cipherboy
3y ago
That looks like a(n unofficial) fork, not contributions to the official upstream repository.
37.
▲
by
cipherboy
3y ago
Citation needed? https://github.com/facebook/zstd/commits/dev/?author=jiaT75
38.
▲
by
cipherboy
3y ago
Sure, but in general the expected value of a HSM is that (especially in FIPS mode) it prevents extraction and accidental leakage of the keys (and maybe at appliance levels has explicit logging). If you're sure you never do a plaintext
39.
▲
by
cipherboy
3y ago
As an example, an offline PKI root backed by a picohsm would be fast enough, given intermediates aren't typically minted that frequently.
40.
▲
by
cipherboy
3y ago
https://csrc.nist.gov/pubs/sp/1800/37/2prd It seems to be intentional exfiltration of key material (either bounded DH keypairs rather than ephemeral or, more likely, exfil of the symmetric channel key).
41.
▲
by
cipherboy
3y ago
Does this also extend to the BUSL?
42.
▲
by
cipherboy
3y ago
I think there's many counter examples to this: Jenkins & Hudson, Illumos & Solaris, LibreSSL & OpenSSL & BoringSSL, LibreOffice & OpenOffice, Spongy Castle & Bouncy Castle, and Webkit & KHTML to name a few.
43.
▲
by
cipherboy
3y ago
Maintainability and feature development mostly. I have a few improvements I'd have liked to have see upstream, but couldn't land due to the vast storage plugin base. You're left writing to the lowest common denominator of 20
44.
▲
by
cipherboy
3y ago
Per https://github.com/orgs/openbao/discussions/147#discussionco... the Alpha is slated for end of the month. No word on GA date yet.
45.
▲
by
cipherboy
3y ago
Thank you for the RFE! Looking at the X-Forwarded-For handling might be good, I wasn't able to add tests for that easily, though maybe the existing test could be used as a template if you get time. I think we depend on nginx or Caddy e
46.
▲
by
cipherboy
3y ago
Happy to answer technical questions about OpenBao as people have, though some might be best directed at the Technical Steering Committee, which I do not represent. :-)
47.
▲
by
cipherboy
3y ago
Kyber Slash (and Kyber Slash II) is a recent one in a very modern, PQC finalist algorithm that is missing from the list if you're looking to expand! This was caused by an integer division by a known constant (KYBER_Q = 3329) under a se
48.
▲
by
cipherboy
3y ago
I agree. I think what OP is talking about is change in the (for rebuilders) source distribution availability, e.g., https://www.redhat.com/en/blog/furthering-evolution-centos-s... -- but as a later blog post point
49.
▲
by
cipherboy
3y ago
Even businesses care about the distinction between OSI-approved and SSPL/BUSL licensed code bases. In the latter, they often cannot host services that use BUSL licensed code which puts risks on the business. Some examples: Do they need
50.
▲
by
cipherboy
3y ago
I don't see how it is irrelevant: you ask if they still count, and the answer is yes, because they contribute rather heavily to OSI-approved code, so they'd count regardless. The real question is, would we consider MongoDB or my f
51.
▲
by
cipherboy
3y ago
Even with the changes to RHEL licensing, Red Hat developers are still encouraged to upstream changes before landing them in Fedora (and in turn, before landing them in CentOS stream and ultimately RHEL). Nearly every developer at Red Hat wo
52.
▲
by
cipherboy
3y ago
I don't believe Microsoft contributes to this project. There are STIGs available for Windows but presumably any automated hardening by Microsoft is proprietary. Likely a new Powershell automation backend would be necessary. The scanner
53.
▲
by
cipherboy
3y ago
There are many projects to automate remediations. One in use by the DoD in this area is OpenSCAP (scanner) and Compliance as Code (benchmark content + automated remediations), lead by Red Hat and contributed to by other Linux vendors. But,
54.
▲
by
cipherboy
3y ago
Note that there may be incompatibilities (as noted in the article) until NIST has published the final revisions. Some specifications are on Round 3 kyber, others are on FIPS 203. This one will interoperate with Bouncy Castle (both Java and
55.
▲
by
cipherboy
3y ago
https://youtu.be/u2Hc5F4hJ60 has that quote and many others!
56.
▲
Peter Schickele, composer and gleeful sire of P.D.Q. Bach, dies at 88
(nytimes.com)
124 points
by
cipherboy
3y ago
|
23 comments
57.
▲
by
cipherboy
3y ago
Like OpenTofu, this will likely take some time and likely will be a blocking step that prevents other contributions until it is done.
58.
▲
by
cipherboy
3y ago
Right, sorry, I wasn't implying that the community should or could add PKCS#11 support, just stating that while TPM support is nominally lacking from Vault Enterprise documentation, it is achievable today via PKCS#11 bridge. :-)
59.
▲
by
cipherboy
3y ago
I don't think this is a valid take. Some, like myself, have left over this issue. Many discussions happened in private for various obvious reasons. But your reasoning at the end was not my understanding. That said, I have nothing but r
60.
▲
by
cipherboy
3y ago
\o do you mind opening issues for these topics for discussion? https://github.com/openbao/openbao/issues/new TPM seal could be addressed with the PKCS#11 TPM bridge (which requires Vault Enterprise). But I&#x
More ›