498 karma · joined August 13, 2009
Building containers with packer is easier than switching to Dockerfiles for existing builds, but does not support fast, incremental build and deploy or tagging. Even without those features, I see no advantages in traditional CM other than the convenience of familiarity and legacy.
I am not aware of any proposed attacks on the approved cipher suites that are anywhere near feasible. TLS deployment is far behind known best practice. We should do something about that.
Immanentize your personal eschaton,
Lil 'B
Securely Yours,
Lil' B
One love,
Lil' B
stunnel DH code inserted into stud.
1) Habit
2) As implemented/deployed in SSL, it still provides some security
RC4 has gotten a bad reputation in large part because of its poor application in WEP that resulted in keys being rapidly recovered by sniffing traffic. The Wikipedia entry is a good place to start http://en.wikipedia.org/wiki/RC4#Security (& numerous references for the original papers/pubs cracking various bits of RC4). The RSA response to RC4 concerns (from WEP) is worth reading, as well http://www.rsa.com/rsalabs/node.asp?id=2009 .
Recommending people unfamiliar with configuring SSL leave defaults alone is only incompatible with our having non-default config if you are implying I don't understand configuring SSL. I doubt that is what you mean, as I am ever the optimist.
Yay!,
Lil' B
"The win here is that losing the RSA key now only allows you to MITM future SSL/TLS connections. This is still a disaster, but it does not allow you to retroactively unwind previous DH exchanges and decrypt earlier captured sessions."
"If you've lost your RSA key, you are well and truly fucked."
Thanks for clearing that up!
Make love not war,
Lil' B
Adam - "However, with a pure RSA ciphersuite, an attacker can record traffic, crack (or steal) your private key at will and decrypt the traffic retrospectively, so consider your needs."
Matt - "Unfortunately, it also includes a very computationally intensive cipher using an ephemeral Diffie-Hellman exchange for PFS. Sounds scary already, doesn't it? ... The problem cipher is DHE-RSA-AES256-SHA [b]."
The first is factual and straightforward. The second is muddled and clearly skewed towards blindly disabling DHE. I believe we are in agreement that it is irrelevant to almost everyone building on nginx: their connection rates are so low they will not notice the overhead introduced by DHE.
I am sniping at enthusiastic ignorance and encouraging others to behave similarly. I hope that is all quite clear now.
Hugs and kisses, Lil' B
Here's my vintage code for scanning SSL configs: https://github.com/b/tlscollect
Here are a couple of must read posts from someone who really knows his SSL business:
http://www.imperialviolet.org/2010/06/25/overclocking-ssl.ht...
http://www.imperialviolet.org/2011/02/06/stillinexpensive.ht...
It's great to learn.
Lil' B
Worshipping at the altar of HATEOAS,
Lil' B
Funktacularly yours,
Lil' B
Yours in perpetual bogglement,
Lil' B
Boundary is building a platform for real-time network operations, visualization, and exploration. We have exciting challenges in high-speed data collection, large-scale data processing, user experience, and interface design. We work with a variety of languages, including Scala, Erlang, C/C++, and Javascript. We're venture-backed and our small, talented team is growing fast. Our jobs page is at https://boundary.com/jobs or you can email us at jobs@boundary.com. If you are great at what you do and want to make a real impact, we'd love to hear from you!
Big ups to the Homo Sapiens posse.
- Lil' B