Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tashian
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Access your homelab securely via mTLS with a YubiKey and ACME device-attest-01
(smallstep.com)
4 points
by
tashian
4y ago
|
1 comments
32.
▲
by
tashian
4y ago
Hi! For this post I developed a smooth and secure mutual TLS workflow for authenticating to a homelab. It combines: - a TLS client certificate and hardware-bound private key stored on a YubiKey (using the YubiKey PIV application) - ACME dev
33.
▲
by
tashian
4y ago
Full disclosure: I work for Smallstep. The recent trend toward "Zero Trust" security has come about in the wake of attacks on internal infrastructure, where having a firewall wasn't enough. There can be lots of ways into inte
34.
▲
by
tashian
4y ago
If I'm understanding correctly, I think they're referring to a case like this: https://www.experian.com/ is the primary domain of the company. https://www.experianidworks.com/ is a "decorated
35.
▲
by
tashian
4y ago
Full disclosure: I work for Smallstep. I love your point about being able to limit trust on hardened systems to your own CA. For servers, in many cases you don't need any CAs in the trust store, because a lot of services will only trus
36.
▲
by
tashian
4y ago
I ran a BBS as a teen, on my Amiga, out of my bedroom, and it was such a fun project for me. At the time, it was expensive to make phone calls outside of your area code. And that was a healthy natural constraint on the community: Nearly eve
37.
▲
by
tashian
5y ago
I'm a lifelong engineer. I started programming when I was 12, studied computer engineering in college. But I've burned out a couple times. Most recently in 2016, burnout prompted a lot of inner work for me. At the time I was VP of
38.
▲
by
tashian
5y ago
It's been great. Very reliable on the hardware side, I've never had any issues with it, but it did take a while for me to get it set up properly.
39.
▲
by
tashian
5y ago
The CA and NTP server would hum along just fine. The DNS servers, less so: CoreDNS is reading my internal DNS zone from an Amazon Route53 private zone. This was my way of dealing with running two DNS servers concurrently, but it wouldn'
40.
▲
by
tashian
5y ago
Yep, a SATA SSD that runs over USB 3.0 is very fast on the RPi4, as long as you make sure "UASP mode" is enabled (this can take bit of tinkering). You don't even need external power, just a $5 USB to SATA cable.
41.
▲
by
tashian
5y ago
I've written about the CA for Smallstep: https://smallstep.com/blog/build-a-tiny-ca-with-raspberry-pi... I'd LOVE to write more about my homelab, but it's a work in progress that continues to evolve, and
42.
▲
by
tashian
5y ago
In my homelab I've got RPis running Minio (S3-compatible block storage), step-ca (local certificate authority), CoreDNS (local DNS), a local gpsd/chrony setup (for local GPS-backed NTP, using the Uputronics GPS hat), shairport-syn
43.
▲
How to Handle Secrets in the CLI
(smallstep.com)
1 points
by
tashian
5y ago
|
0 comments
44.
▲
by
tashian
6y ago
It looks like a coronavirus
45.
▲
by
tashian
6y ago
TLS does have a mode that uses a pre-shared key, but in TLSv1.3 I believe it's only used for session resumption. Edit: Also, I recently learned about DNS Certification Authority Authorization (CAA) records. You can specify which of the
46.
▲
The Embarrassing State of Enterprise Acme Support
(smallstep.com)
4 points
by
tashian
6y ago
|
0 comments
47.
▲
The Embarrassing State of Enterprise Acme Support
(smallstep.com)
11 points
by
tashian
6y ago
|
0 comments
48.
▲
by
tashian
6y ago
The ACME protocol (used by Let's Encrypt / ZeroSSL) can be used with internal infrastructure, too. I know that some folks already use Let's Encrypt to issue internal TLS certificates, but that's not always ideal. Step CA
49.
▲
by
tashian
6y ago
The "zone index" they mentioned can make for even more unwieldy URLs than described here. A browser doesn't have to accept: http://[fe80::1ff:fe23:4567:890a%eth0]/ Because of the ambiguity around '%'
50.
▲
by
tashian
6y ago
That sounds like a great option too, depending on your situation. One difference is that the CA is on the hardware key, but the cert (and its private key) is not. Imagine you're on a team of 50, and anyone on the team might need emerge
51.
▲
by
tashian
6y ago
Yes! Shameless plug — we (smallstep.com) offer a service that makes this frictionless at scale and super easy to set up. You'll never want to go back to public keys.
52.
▲
by
tashian
6y ago
Hey there, I wrote this post. It's a great question. One benefit of using certificates for emergency access is that SSHD logging can be configured to show a lot more detail about the certificate that was used. With public keys, there i
53.
▲
by
tashian
6y ago
Hey there — I'm the author of this post. There's a few scenarios where I imagined this approach being useful: * If you have any kind of remote dependency in your SSH auth flow (LDAP, or an online CA, or automated Ansible playbooks
54.
▲
So you want to talk about race in tech
(techcrunch.com)
2 points
by
tashian
6y ago
|
0 comments
55.
▲
The Poetics of CLI Command Names
(smallstep.com)
117 points
by
tashian
6y ago
|
75 comments
56.
▲
by
tashian
6y ago
And on an international keyboard it’s ~~, because ~ defaults to being a character modifier. If you nest SSH sessions, then you add more ~s. So in your fifth nested SSH session on an international keyboard the escape sequence would be \n~~~~
57.
▲
by
tashian
7y ago
One unmentioned reason this is powerful: It avoids concurrency bugs and inconsistencies introduced by write skew, in cases where the application layer (eg. Ruby/Python) makes business logic decisions based on data that has become stale
58.
▲
by
tashian
8y ago
Hmmm... I may have been better off with "and" instead of "but" here, because I was agreeing with the parent comment and adding my own encouragement. scruple took no clear stance in the original comment on whether empathy
59.
▲
by
tashian
8y ago
I agree. I think talking about code is a critical skill, but not everyone has a strong practice of doing it. When I was first learning to code I never had anyone to talk to about my code, so I didn't get to learn the vocabulary until l
60.
▲
by
tashian
8y ago
That's really the worst. When people copy and paste something like NVC insincerely. It's not a "tool" that you "implement" in your speaking style. But, when people are taking on things like this at first, it is
More ›