Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
diogomonicapt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Lessons Learned Using GraphQL for iOS
(medium.com)
3 points
by
diogomonicapt
8y ago
|
0 comments
2.
▲
A Pirate's Take on Command vs. Leadership
(diogomonica.com)
6 points
by
diogomonicapt
8y ago
|
0 comments
3.
▲
by
diogomonicapt
9y ago
Don't disagree; I think what I actually tried to argue for was doing both: segregate data access to a new, minimal, service that also requires a key in an HSM to operate.
4.
▲
by
diogomonicapt
9y ago
You can definitely do this in public cloud HSMs. Azure: https://azure.microsoft.com/en-us/pricing/details/key-vault/ AWS: https://aws.amazon.com/cloudhsm/ The only thing you're
5.
▲
Crypto Anchors: Exfiltration Resistant Infrastructure
(diogomonica.com)
142 points
by
diogomonicapt
9y ago
|
57 comments
6.
▲
Why you shouldn't use ENV variables for secret data
(diogomonica.com)
2 points
by
diogomonicapt
10y ago
|
0 comments
7.
▲
by
diogomonicapt
10y ago
My unstated assumption was that when calling something like imagetragick you would be doing the appropriate privilege dropping using setuid and setgid. This is obviously not necessarily the case, but it's at least a lot more common t
8.
▲
by
diogomonicapt
10y ago
The problem is applications unintentionally leaking the ENV. Think a hoptoad exception that attaches the current ENV to the report that sends up to the remote server. Or think about you exec'ing imagemagik and now the process running p
9.
▲
by
diogomonicapt
10y ago
Way better than I could have answered ;)
10.
▲
by
diogomonicapt
10y ago
We explicitly chose not to support secrets as ENV variables, since they are prone to being leaked (child processes inhering parent's env; easy to leak ps -e; bug reports usually include ENV of the application; core dumps include ENV of
11.
▲
by
diogomonicapt
10y ago
- We're working on external store support. First implementation will probably be w/ Vault, but we would love for this to come from the community. - If you have access to the managers, you have access to all the secrets (and access
12.
▲
by
diogomonicapt
10y ago
Exactly. The new version of compose supports defining docker secrets inside of the compose file.
13.
▲
by
diogomonicapt
10y ago
Yes: https://github.com/docker/docker/pull/30637
14.
▲
by
diogomonicapt
10y ago
Thanks! - Exposing secrets as in-memory files has a lot of advantages over ENV variables (harder to leak). - We already started updating a few images (MySQL, for example), so they can use Docker secrets. - Definitely not DDC only, but note
15.
▲
by
diogomonicapt
10y ago
You can make a PCI compliant installation w/ Docker yes.
16.
▲
by
diogomonicapt
10y ago
I think with this release things have come full circle for me. I was part of the team that 5 years ago built Keywhiz at Square, starting the whole "secrets should be files exposed as an in-memory filesystem" thing. Building it a s
17.
▲
Why should hard be secure enough? Information and non-invertibility
(diogomonica.com)
58 points
by
diogomonicapt
10y ago
|
46 comments
18.
▲
by
diogomonicapt
10y ago
Author here, I actually added a footnote exactly because of that fact: https://diogomonica.com/2017/01/11/hitless-tls-certificate-r...
19.
▲
Hitless TLS Certificate Rotation in Go
(diogomonica.com)
84 points
by
diogomonicapt
10y ago
|
10 comments
20.
▲
Build once run where? Migrating my blog to hyper.sh
(diogomonica.com)
1 points
by
diogomonicapt
10y ago
|
0 comments
21.
▲
Increasing Attacker Cost Using Immutable Infrastructure
(diogomonica.com)
110 points
by
diogomonicapt
10y ago
|
36 comments
22.
▲
by
diogomonicapt
11y ago
Disclaimer: I work for Docker For the security enthusiasts out there, Docker 1.10 comes with some really cool Security focused additions. In particular: - Seccomp filtering: you can now use bpf to filter exactly what system calls the proces
23.
▲
by
diogomonicapt
12y ago
I agree that the title is more link-baity than it should. For what it's worth, part of it was just a witty title.
24.
▲
by
diogomonicapt
12y ago
Agreed. The article did stem from me reading blogposts where people were interpreting the XKCD comic into: just chose four words instead of one password.
25.
▲
by
diogomonicapt
12y ago
I think the answer is not yet. Apple's TouchID is a great example of a frictionless authentication mechanism that can be easily augmented with a password to achieve two different factors, but the reality is that isn't a lot of tha
26.
▲
by
diogomonicapt
12y ago
Sorry man, no product.
27.
▲
Distance between your IP and W3C Location
(location.diogomonica.com)
4 points
by
diogomonicapt
14y ago
|
0 comments