Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mmalone
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
mmalone
6y ago
If you have a group of services running inside a perimeter with secure entrypoint(s), issuing client certificates allows you to coarsely segment service-to-service interactions within that perimeter to contain blast radius from a malicious
32.
▲
by
mmalone
6y ago
In my response from three hours ago about threat model I said “service authentication helps control the blast radius if someone gets inside your perimeter”. I’ve been saying that I think we mostly agree for a while. If you have a perimeter
33.
▲
by
mmalone
6y ago
The certificate is still containing blast radius when the attacker is in your network and limiting the insider threat from people who have access to some subset of production. Without a cert, they’d be able to access everything. With a cert
34.
▲
by
mmalone
6y ago
You’re putting words in my mouth again. I didn’t say those were the only two options. I asked what your silver-bullet alternative to mTLS is that has no issues of its own. The position seems to be that mTLS has problems, so don’t use it. Bu
35.
▲
by
mmalone
6y ago
It's not intended to be sleight of hand. Confidentiality is the gateway drug. The argument is that, once you're using TLS for that, the incremental cost of adding client certificates and doing mTLS to reduce blast radius is lower.
36.
▲
by
mmalone
6y ago
Someone just sent me a tweet from @halvarflake where he asked for the threat model under which service-to-service TLS is the best solution. I wanted to cross-link these threads since I think they're related: https://twitter.
37.
▲
by
mmalone
6y ago
You’d use that for service-to-service stuff, to mutually authenticate services (not users), as well? I’ve always thought of AWS IAM as: great for my-service-to-cloud-service, not so great for my-service-to-my-service. I haven’t looked at AW
38.
▲
by
mmalone
6y ago
Woof. Literally nobody likes x509. Is anyone seriously working on an alternative? I think there’s room for a more modern, simpler cert format. Sort of relatedly, I actually really like JWK for representing keys. Do you think a professionall
39.
▲
by
mmalone
6y ago
Appreciate the thoughtful response! Reading it over, I think we mostly agree on the facts. It's easy to do mTLS and x509 wrong. The question, then, is what's easier / more secure: doing mTLS/x509 right or doing something
40.
▲
by
mmalone
6y ago
Yea that's reasonable, but there are pros and cons and it's also definitely an opinion :). I don't see the problem with piping help text through a pager (that's literally all `man` is doing). Alternatively, a tool can us
41.
▲
by
mmalone
6y ago
They're not saying you shouldn't provide command-line help. Just that you should deliver them through a `help` subcommand and/or through a `--help` flag (like `git` does) because people don't find man pages and because m
42.
▲
by
mmalone
6y ago
Yep. Not perfect... type systems have come a long way since PowerShell did it. But it's a good start. Look at stuff like PowerShell secure strings for an example of the sort of neat stuff you can do.
43.
▲
by
mmalone
6y ago
Yea, like, imagine if posix pipes and command-line flags could be typed.
44.
▲
by
mmalone
6y ago
Recent macOS versions don't have `ssh-askpass`, and it's weirdly hard to add one. Since agent confirmation depends on askpass, I don't think there's an easy way to get this work on macOS. Aside from the missing context y
45.
▲
by
mmalone
6y ago
YES. It would be so easy for OpenSSH to fix agent forwarding. Just need to limit authority and/or ask for consent for a particular action.
46.
▲
by
mmalone
6y ago
I wish there was a better way manage telemetry for open source. We have this problem at smallstep, too. We don’t have any telemetry — nothing is instrumented / nothing phones home — but that means it’s really hard to know which feature
47.
▲
by
mmalone
6y ago
In general I'd say SSHing from a remote box to another remote box is a non-issue since you can always use some sort of tunneling/bastioning to make that work. It's when you want to use some other tool that tunnels over SSH
48.
▲
by
mmalone
6y ago
If you like ssh-import-id to pull keys from GitHub, you’ll love AuthorizedKeysCommand to pull keys from GitHub. Depending on use case, though, this can be a bit sketch. At smallstep we like SSH certificates, which make life similarly easy
49.
▲
by
mmalone
6y ago
Yea we like certificates at smallstep. We’ve got a couple[1] other[2] posts[3] that cover them pretty well. Should have probably made a more prominent mention though :). [1] https://smallstep.com/blog/use-ssh-certificat
50.
▲
by
mmalone
6y ago
Seems the ideal solution would be to trigger push-to-allow for signing requests that come in via agent forwarding, but not for local requests. I’ve been thinking about a reliable & secure way to do this. A modified OpenSSH client could
51.
▲
by
mmalone
6y ago
That works for bastions, but not other use cases. One common one is pushing & pulling from git on a remote dev box. Or if you want to SCP something between remote machines without having to pull it down locally. Agent forwarding is the
52.
▲
by
mmalone
6y ago
So you’re saying SCP will tab complete through the control master socket? Neat.
53.
▲
by
mmalone
6y ago
Check out our single sign-on for SSH stuff at smallstep (where I work). Either in open source[1] or our product[2]. The hassle of 2FAing all the time is one of the big reasons I love single sign-on for SSH. Basically, you do 2FA when you&#x
54.
▲
by
mmalone
6y ago
Last time I launched a new website it took less than a month for someone to let us know that we'd forgotten to configure a AAAA and our site was inaccessible for them. And that was at new website traffic volume. So yea, GitHub definite
55.
▲
by
mmalone
6y ago
Nice. `Match exec` is one of my favorite things. It's too bad the command being passed to `ssh` (if there is one) isn't available as a `TOKEN` (as far as I can tell). That would put a bow on everything.
56.
▲
by
mmalone
6y ago
I've always wondered what this is useful for. So it's purely for performance? Why is it faster to establish the connection? Does it re-use the authentication from the existing ControlMaster too, so you skip the handshake? Seems li
57.
▲
by
mmalone
6y ago
Disclosure: not OP, but work at smallstep Smallstep has a product[1] that's a lot like gravitational teleport. That's how we got deep enough into SSH to write this post. Teleport isn't bad. The two biggest differentiators are
58.
▲
by
mmalone
6y ago
We’re hiring at smallstep ;D
59.
▲
by
mmalone
6y ago
That `tmux` bit is clever. Wonder if you could do that in a `ForceCommand` or something like that so you don’t need to type that part either?
60.
▲
by
mmalone
6y ago
You can also use the `ProxyJump` directive in your `~/.ssh/config`, which is the same as `-J` on the command line. So, for example: Host host_final ProxyJump user1@host1 will do the same thing as `-J user1@host`,
More ›