HNHacker News
TopNewBestAskShowJobs

dustinrcollins

216 karma · joined April 5, 2013

[ my public key: https://keybase.io/dustinmm80; my proof: https://keybase.io/dustinmm80/sigs/to1Z-wR3B-Czo7pbAWV1RaseYN9qXa1bGyOjSv0iTFM ]
submissionscomments
dustinrcollins··on Infosec's Jerk Problem (2013)
Tribalism is really hurting the progress that security folks could be making. Development and operations are starting to collaborate and make huge gains in productivity. Rebranding security as a component of quality can help.

Coming into meetings with other teams with a list of (often unfounded) assumptions does not help anyone. I wrote about this a bit last year: https://blog.conjur.net/devops-and-security-the-five-monkeys

dustinrcollins··on Vault – A tool for managing secrets
The policies look like they'd be a bear to manage since they are path- and not role-based. In order to implement least privilege with multiple actors you'd have to be really careful with your paths.

Example: 2 apps. App 1 needs secrets A B and D. App 2 need secrets A B and C.

So we need to set up our paths in a way that App 1 can get A and B and C, but not D. App 2 needs C but not D. Now when you want to modify secret access from your apps you have to rethink how your paths are set up.

When you're instead assigning permissions to roles this is a lot easier. An example: http://blog.conjur.net/what-is-a-devops-secrets-server

dustinrcollins··on Vault – A tool for managing secrets
http://conjur.net/
dustinrcollins··on Security of Infrastructure Secrets
We have been audited by a 3rd party and incorporated all of their suggestions in the latest 4.4 release.

http://blog.conjur.net/conjur-4-4-released

One of their stipulations for the audit was that we don't use it for promotional purposes so I guess a NDA is required to discuss details.

The tech we use for encryption of secrets is definitely open source here: https://github.com/conjurinc/slosilo

Conjur isn't built on in-house cryptographic software - it uses trusted open-source tools - OpenSSL, PAM and so on.

Most of our work is open-source https://github.com/conjurinc https://github.com/conjur-cookbooks

dustinrcollins··on Security of Infrastructure Secrets
When using Hosted Chef you can't generate a private key and upload it. You create a user, their system generates your key pair and displays the private key one-time-only for you to store somewhere. A user in Chef can only have one keypair at a time. This is just a limitation of their system we have to work with.

It's important to note that the 'user' here in Hosted Chef is not a person, it is an identity in the Chef server that is allowed to upload cookbooks. Its scope is limited to only that.

Rotating the deploy user's key when using HostedChef is a 1 step process, using knife and Conjur together

``` knife user reregister "conjurbot" | conjur variable values add hostedchef/conjurbot/private_key ```

The stdout of `knife user reregister` is the private key so you can update the variable in Conjur without even seeing the value. You could run this in a cron job if you wanted. Your CI system responsible for uploading cookbooks will pull the new private key next time it runs.

Again, not ideal that Hosted Chef only allows you one keypair per user but we can minimize the threat by rotating the key frequently.

dustinrcollins··on KeyBox: A better way to SSH
conjur is a more robust solution for SSH management and avoids the single point of failure. Treating services and code as first-class citizens is not something LDAP excels at.

http://www.conjur.net

dustinrcollins··on [dead]
You could also just disable spotlight:

sudo launchctl unload -w /System/Library/LaunchDaemons/com.apple.metadata.mds.plist

and use [Alfred](http://www.alfredapp.com/).

dustinrcollins··on Ask HN? State of python greenfield development as to versions?
2.7, mostly. Check here though; if the libs you use are green consider using 3.

https://python3wos.appspot.com/

dustinrcollins··on Ask HN: What are the best technologies you have worked with in 2013?
Vagrant, Chef, AWS CloudFormation. Writing your infrastructure as code saves you a ton of time and headaches.
dustinrcollins··on Ask HN: Who is hiring? (July 2013)
Carbonite (http://www.carbonite.com) - Boston, MA (no remote)

Carbonite leads the consumer cloud backup category with nearly 1.5 million paying customers and 85% retention rates.

We are looking for engineers to join our Labs team, a small team that ships MVP apps to test viability and explore new possibilities in the market. We have a startup feel, with the financial backing of an established company.

We are looking for people excited about new technologies and working full-stack. We write a lot of services in Python, so if you love Python you'll fit right in. Some of the other stuff we work with: AWS (EC2, CloudFormation, S3, etc), Cassandra, AngularJS, Chef, and many more. We write clients for Windows/Mac/iOS/Android.

We work in Scrum, release every 2 weeks, and iterate based on user feedback. There is a lot of freedom in this position to work on what you like and investigate new ideas and tech.

If you're interested in the position, send me an email with some info about yourself, a resume and your Github (if you have one).

My name is Dustin and I am an engineer on the Labs team. I look forward to hearing from you! dcollins@carbonite.com

dustinrcollins··on Ask HN: What do you use to produce software documentation?
I think it's fine to document these things in Sphinx as well. Creating a docs repo and writing .rst files to cover these requirements can be useful, and then you can move them as needed as your project progresses.
dustinrcollins··on Ask HN: Who is hiring? (June 2013)
Carbonite (http://www.carbonite.com) - Boston, MA

Carbonite leads the consumer cloud backup category with nearly 1.5 million paying customers and 85% retention rates.

We are looking for engineers to join our Labs team, a small team that ships MVP apps to test viability and explore new possibilities for the company. We have a startup feel, with the financial backing of an established company.

We are looking for people excited about new technologies and working full-stack. We write a lot of services in Python, so if you love Python you'll fit right in. Some of the other stuff we work with: AWS (EC2, CloudFormation, S3, etc), Cassandra, AngularJS, Chef, and many more. We write clients for Windows/Mac/iOS/Android.

We work in Scrum, release every 2 weeks, and iterate based on user feedback.

If you're interested in the position, send me an email with some info about yourself, a resume and your Github (if you have one).

My name is Dustin and I am an engineer on the Labs team. I look forward to hearing from you!

dcollins@carbonite.com

dustinrcollins··on Ask HN: How to Open Source an already live project?
There was a talk at PyCon US this year covering several of the questions you have.

How (Not) to Build an OSS Community

http://pyvideo.org/video/1742/how-not-to-build-an-oss-commun...

dustinrcollins··on Ask HN: Who is hiring? (May 2013)
Carbonite (http://www.carbonite.com) - Boston, MA

Carbonite leads the consumer cloud backup category with nearly 1.5 million paying customers and 85% retention rates.

We are looking for engineers to join our Labs team, a small team that ships MVP apps to test viability and explore new possibilities for the company. We have a startup feel, with the financial backing of an established company.

We are looking for people excited about new technologies and working full-stack. We write a lot of services in Python, so if you love Python you'll fit right in. Some of the other stuff we work with: AWS (EC2, CloudFormation, S3, etc), Cassandra, AngularJS, Chef, and many more. We write clients for Windows/Mac/iOS/Android.

We work in Scrum, release every 2 weeks, and iterate based on user feedback.

If you're interested in the position, send me an email with some info about yourself, a resume and your Github (if you have one).

My name is Dustin and I am an engineer on the Labs team. I look forward to hearing from you!

dcollins@carbonite.com