Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mreinsch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
mreinsch
12y ago
Why is that? Isn't that exactly the same problem whether you're using environment variables or a config file?
2.
▲
by
mreinsch
12y ago
This is indeed an issue, though with a modern cloud based infrastructure and management systems there is no longer a need to create backups from your production servers. They can be automatically recreated and no important data is stored on
3.
▲
by
mreinsch
12y ago
as long as you don't store your config then in the same repository as your code, that works fine for me.
4.
▲
by
mreinsch
12y ago
sniffing isn't the main issue I'm trying to avoid, it's accidental exposure. I.e. minimising the risk that during normal operations the secrets get exposed somehow.
5.
▲
by
mreinsch
12y ago
I have to admit that I don't know a thing about TPM. Like is it also available in virtual environments like AWS is providing? How could this be automated? You don't want to enter a passphrase every time a server (re)boots. Would l
6.
▲
by
mreinsch
12y ago
Thanks for that idea of deleting sensitive environment variables. I like that for hosters such as heroku which use ENV variables for config (including secrets) by default.
7.
▲
by
mreinsch
12y ago
Thanks. I'm mainly looking at this from the point of how your secrets could be accidentally exposed. I applaud to postfix for sanitising the ENV, and it's very good practice to do so. But are all the frameworks doing it correctly?
8.
▲
by
mreinsch
12y ago
I agree that ENV variables are useful for general configuration, that's exactly what they were invented for... ENV variables are not restricted by user though, your process can spawn another process under a different user and give it t
9.
▲
by
mreinsch
12y ago
The permissions on our chef repository are different. We can give access to the main code repository without giving access to the chef repository. Alternatively, if you're running on AWS you could also fetch the secrets config file fro
10.
▲
by
mreinsch
12y ago
You're right that a tool which runs under the same user could read your config file and thus could access to your secrets. But there is one main difference: that tool would need to do so explicitly, with the intent of reading (and poss
11.
▲
Samurai Loren Fykes of the Third Gundan releases recommendation app Quchy
(beaconreports.net)
3 points
by
mreinsch
13y ago
|
0 comments
12.
▲
Hacker News Tokyo Japan Meetup #19 – 6th of February, 2013
(hntokyo.doorkeeper.jp)
22 points
by
mreinsch
14y ago
|
8 comments
13.
▲
by
mreinsch
15y ago
yeah!
14.
▲
by
mreinsch
16y ago
great, looking forward!
15.
▲
by
mreinsch
16y ago
Asiajin ( http://asiajin.com/ ) is covering Japanese startups (among other stuff)
16.
▲
by
mreinsch
16y ago
Yes, you'll be able to get in. But it'll be ¥3,000 and you'll get two drink tickets instead of the buffet ticket. Check the event description on http://tbtpe.doorkeeper.jp/ for all the details. Anyway, hope to see you there. I'll be he
17.
▲
Updating a real world application to Rails 3
(mobalean.com)
1 points
by
mreinsch
16y ago
|
0 comments
18.
▲
by
mreinsch
16y ago
How are you running delayed_job or other custom daemons?
19.
▲
by
mreinsch
16y ago
Great! I'll make sure to come along again!