HNHacker News
TopNewBestAskShowJobs

babawere

1,603 karma · joined December 21, 2012

submissionscomments
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Both, honestly. Fun and production intent. But `production` here is very specific, embedded in a single Go binary, a single *.db not a CLI tool (the cli you see there is just for inspection) for developer or CI.

The problem fnox solves is great, unified access to secrets across dev, CI, prod with cloud backends. That's a different layer of the stack.

Keeper solves a lower-level problem: you have a Go process (a load balancer, a control plane, a daemon) that needs to store secrets inside its own database not in a separate file, not in a cloud vault, not in env vars. Secrets that need per bucket isolation, audit trails, and crash-safe rotation.

Here is my thinking :

- fnox = how your CLI and deploy scripts get secrets

- Keeper = how your running binary stores secrets at rest

Different problems, Could I build Keeper on top of fnox? Probably. But then I'd have a file on disk with secrets that fnox manages which is exactly the problem I wanted to eliminate.

babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
The first bug has been confirmed however The second `vulnerability` would only be exploitable if an attacker could also break SHA-256 preimage resistance to forge valid checksums ??? correct me if am wrong
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Thanks for sharing this. secret looks really well thought out, the three-layer key hierarchy is impressive. And using `age` is a solid choice. once considered it.

Different trade-offs though, Keeper is library first embedded. secret does per version keys with symlink switching - nice, Keeper does per-bucket DEK isolation + audit chains. Both solve "encrypted local storage" but for different workflows.

I'll definitely be looking through your code for ideas

babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Thanks for the look. On the verification hash, you're right, SHA256 would work there. Argon2id was overkill, I agree 100%.

The crash-safe WAL is the part I'm most nervous about too. That's exactly why I posted this. I want eyes on the rotation logic specifically.

And yeah, single bbolt db is a limitation. I could have used pebble or any other, but trade-off for simplicity (a single *.db). A true WAL will need external file. The storage is pluggable though also open to improvement.

Still very young.

babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
So have been told. Will definitely look for a better name
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
thanks for the update ... will definitely look for a better name
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Honestly… the initial use case is to hide certs from the file system and secrets from the environment. However, this can be extended.

The primary issue has been not being able to manage an encrypted storage system… the main goal is to have something that can be audited, not just secured.

yes 100% ... embeded

babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Definitely … agents cannot access your password unless you save it to the environment too. However it's better to use resolvers ... depending on your use case
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
not when you need an audit system
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
I was thinking its better to be boring-correct :)
babawere··on Show HN: Keeper – embedded secret store for Go (help me break it)
Even when you have a proper function and use AI for auto documentation, it silently changes it (insane) … I will defiantly fix this.
babawere··on VSCodium – An Open Source Visual Studio Code Without Trackers
Can you please explain in details?
babawere··on Is PrivDog another Superfish
Its came with the version 7 and you can see here https://help.comodo.com/topic-72-1-451-6840-.html it says

You can install PrivDog while installing Comodo Internet Security or by downloading the app from www.privdog.com/downloads.html

I saw the option to install PrivDog while Installing the Comodo Internet Security

babawere··on Is PrivDog another Superfish
Why would comodo promote such a software ???
babawere··on Is PrivDog another Superfish
Its bad enough because this was bundled with Comodo Internet Security ( https://help.comodo.com/topic-72-1-451-6840-.html and https://help.comodo.com/topic-169-1-413-6109-.html )
babawere··on Simpler and faster GC for Go
Dmitry Vyukov Bug https://groups.google.com/forum/#!topic/golang-nuts/MnsJ8_F7...
babawere··on Go is boring
I think you are evaluating 'go' based on feature set rather than the amount of friction a developer experience when using it to develop a good product.

C++ is fantastic but I personally experience far less friction when working with 'go' for most of my task.

babawere··on Tptacek's Review of "Practical Cryptography With Go"
Is your book also based on golang crypto lib ?
babawere··on Taking Google’s QUIC For a Test Drive (2013)
Form https://docs.google.com/presentation/d/13LSNCCvBijabnn1S4-Bb... over 13 revised version, and definitely going to improve this 2014
babawere··on QUIC: next generation multiplexed transport over UDP
Interesting ...
babawere··on Toward Go 1.3
Form what language to what language ?
babawere··on Toward Go 1.3
Its as been a research project for a very very very long time now ...
babawere··on The Research Problems of Implementing Go
They have been thinking about for a very very very long time now, i wonder how much longer since there are 2 release in a year and a lot is yet to be done.
babawere··on The Research Problems of Implementing Go
This particular slide does not support keys ... use the arrow keys.
babawere··on Ask HN: Decode Youtube 500 page
1. Non-standard base64 and 2. Definitely Compressed ... by guess would be snappy compression 3. Possibility of serialization using protocol buffer 4. not sure if such information would be encrypted after such a server failure
babawere··on Web Framework Benchmarks - Round 8
you also need check the errors , most of the languages in to 12 returned too many errors or failed during the request
babawere··on Pointer Tagging in Go
Am still surprised myself ... nice one
babawere··on Why Scala is the best language available today
The best Java improvement :)
babawere··on Go 1.2
+1 for lack of good IDE .. See https://news.ycombinator.com/item?id=6808936 for Vote For Official IntelliJ GOLANG Plugin
babawere··on How old are you and what's your oldest code online?
Can't remember when i saw something like this last
Page 1 of 2Next →