HNHacker News
TopNewBestAskShowJobs

mreinsch

31 karma · joined February 27, 2009

I’m a passionate software developer & architect with a background in software engineering and computer science.

Professionally I’ve been building web based solutions since 2000, using Ruby since 2006 with Ruby on Rails following in 2008. I love working on general architecture and backend topics and used a wide range of tools and technologies there.

[ my public key: https://keybase.io/mreinsch; my proof: https://keybase.io/mreinsch/sigs/A9OLELaI2cpWzrv_qpouqEdjxm0KWYGtHcuJkpG70bs ]

submissionscomments
mreinsch··on Environment Variables Considered Harmful for Your Secrets
Why is that? Isn't that exactly the same problem whether you're using environment variables or a config file?
mreinsch··on Environment Variables Considered Harmful for Your Secrets
This is indeed an issue, though with a modern cloud based infrastructure and management systems there is no longer a need to create backups from your production servers. They can be automatically recreated and no important data is stored on them.
mreinsch··on Environment Variables Considered Harmful for Your Secrets
as long as you don't store your config then in the same repository as your code, that works fine for me.
mreinsch··on Environment Variables Considered Harmful for Your Secrets
sniffing isn't the main issue I'm trying to avoid, it's accidental exposure. I.e. minimising the risk that during normal operations the secrets get exposed somehow.
mreinsch··on Environment Variables Considered Harmful for Your Secrets
I have to admit that I don't know a thing about TPM. Like is it also available in virtual environments like AWS is providing? How could this be automated? You don't want to enter a passphrase every time a server (re)boots. Would love to hear if anybody successfully used that.
mreinsch··on Environment Variables Considered Harmful for Your Secrets
Thanks for that idea of deleting sensitive environment variables. I like that for hosters such as heroku which use ENV variables for config (including secrets) by default.
mreinsch··on Environment Variables Considered Harmful for Your Secrets
Thanks. I'm mainly looking at this from the point of how your secrets could be accidentally exposed.

I applaud to postfix for sanitising the ENV, and it's very good practice to do so. But are all the frameworks doing it correctly? Maybe some code is then also just spawning new processes without sanitising? You could argue that's a bug then (which I completely agree), but not all projects are run like postfix...

mreinsch··on Environment Variables Considered Harmful for Your Secrets
I agree that ENV variables are useful for general configuration, that's exactly what they were invented for...

ENV variables are not restricted by user though, your process can spawn another process under a different user and give it the same environment. It's the nature of the environment that it is usually inherited from the parent which causes the issues when we're talking about secrets.

mreinsch··on Environment Variables Considered Harmful for Your Secrets
The permissions on our chef repository are different. We can give access to the main code repository without giving access to the chef repository.

Alternatively, if you're running on AWS you could also fetch the secrets config file from an S3 bucket which is only accessible by your production servers.

mreinsch··on Environment Variables Considered Harmful for Your Secrets
You're right that a tool which runs under the same user could read your config file and thus could access to your secrets.

But there is one main difference: that tool would need to do so explicitly, with the intent of reading (and possibly exposing) your secrets. For me, that's a huge difference from having the secrets being implicitly available to the process through the processes environment.

mreinsch··on Hacker News Tokyo Japan Meetup #6 – Friday 24th of June
yeah!
mreinsch··on HN Bounenkai Party in Tokyo Japan - Sun, 19th of December
great, looking forward!
mreinsch··on Startups in Japan (Tokyo)?
Asiajin (http://asiajin.com/) is covering Japanese startups (among other stuff)
mreinsch··on Startups in Japan (Tokyo)?
Yes, you'll be able to get in. But it'll be ¥3,000 and you'll get two drink tickets instead of the buffet ticket. Check the event description on http://tbtpe.doorkeeper.jp/ for all the details. Anyway, hope to see you there. I'll be helping out at the door as well...
mreinsch··on Delayed_job (and other daemons) in a production environment
How are you running delayed_job or other custom daemons?
mreinsch··on Tokyo Japan Hacker News Meetup #2 – Friday 18th of June
Great! I'll make sure to come along again!