5 karma · joined September 18, 2022
I’m very surprised that Roon does UNPnP for own port, potentially exposing home network through some zerodays. For that money it has to do reverse tunneling or something like that.
appreciation and OS aside, systemd-creds relays long-lived creds into long-lived processes, and author's AI slop attempts at short-lived/on-demand injections. Apparently, author's AI slop gets a lot of iterations, but has not much of external scrutiny yet.
i know other people partitioning their secrets into multiple keepassx vault files, so the argument about using the same password manager can be interpreted differently.
Other 1pass is a great UX. It was even greater before Electron refactor and non-subscription model.
Where I got stuck was at the Secure Enclave storing biometric-crypted payloads in the keychain, but couldn’t get it to work without Apple Developer subscription for code signing, otherwise these features wouldn’t work. And nobody with an Apple Developer subscription wants to sign someone else’s code, obviously. I really wonder why Apple itself, or any other reputable company, didn’t publish an utility like this already - it’s also a trust issue, when you run code like this.
The issue is that /usr/sbin/security invocations can be obscured to read from keychain, but require password typing every time, which is annoying. And lazy people can just hit “trust” by mistake. And then it’s just another clear text, but more annoying to reach.
Even though, it may be possible to show a touchID prompt in two other scenarios: - encrypting payload with a key stored in the enclave - then it becomes closer to SOPS approach. Age plugin for sops also supports using private keys on yubikey, by the way. But SOPS UX feels clunky. - just calling the APIs to show touchID as part of the application logic, like all modern password managers do. But then you really have to trust the password manager or the tool that does it, because touchID doesn’t equal security in this case.
Some password managers support CLI, SDK, and Terraform providers for working with their secrets, but that requires an IPC enabled, potentially increasing the risk for the other secrets stored in the same password manager.
Oh well, tough choices everywhere.
The issue with less popular data pipeline projects is that they’re less stable in production
https://www.amazon.com/Power-Tools-Third-Shelley-Powers/dp/0... (old but gold) https://www.amazon.com/UNIX-Linux-System-Administration-Hand...