52 karma · joined December 8, 2017
As it turns out, our coworker’s server was also publicly exposing the kubelet ports (tcp 10250, tcp 10255). Although the problem here was obvious, it should raise some questions about your own Kubernetes deployment, as it did for us.
> The content entered into the text box is accessible simply by visiting a link, which means that the data is not end to end encrypted
Me thinks you don't quite understand what end to end encryption means. When you visit pass.sh it forces you onto a TLS session. Anything you enter into that box is encrypted in transit. The data is encrypted in the database, and the password deletes itself from the database automatically after X views and/or X days.
I expected more from a "senior engineer at Virtu" but now I know what company to stay away from. Thanks.
If you cant understand the very basic security control there then I really can't help you. You sound like someone who has been stuck in IT too long.
You are kidding yourself if you think relying on over a support agent to verify identity is better than the solution here. Humans are inherently fallable as social engineering has proven time and again.
but yeah that backend validation is on my radar.
Thanks for checking me out
Firstly, this project is open source. If you suspicious of where the data is being stored or my intentions, you are free to fork and run it yourself.
That being said.. I am not claiming to have achieved some novel security accomplishment. Yes, this is a simple symmetric encryption using a vetted crypto lib, backed by a key value store, and using UUID4 to generate the links.
Its a trade of for convenience and security. It's better than emailing passwords in plaintext and makes security more accessible to folks who dont have the time/incinlination/technical ability to set up keybase and/or estbalish PKI for sharing secrets.
Understand the audience this is targeting..