Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a bit scary how much I am being downvoted for asking what I believe to be a reasonable question. I was expecting someone from the new project to give a quick response with a few points of assurance, and instead I am getting told to go to the very group that downvoters do not trust. This does not make sense to me.


There's nothing scary about being downvoted on HN, but if karma is your goal, I wouldn't start by labeling a simple (and frankly 100% expected) fork a holy war.

I'm not sure I understand your concerns in the previous comment. What would cause you to constantly update your YAML, and why are you just now worried about a rogue dev? Also, who doesn't trust whom?

I see three primary differences between HashiCorp Vault and OpenBao:

1. License: BSL vs. MPLv2.

2. Development model: cathedral vs. bazaar.

3. Maturity: production vs. barely started.

It sounds to me like you don't care about the license, trust cathedral more than bazaar, and value the maturity of the incumbent Vault project. If you're currently a Vault user, I would stay the course for now.

I don't think there's any particular mistrust of HashiCorp in the sense that they will compromise your security, either deliberately or incompetently. However, there is an awareness that their interests aren't necessarily aligned with their customers'.


> It's a bit scary how much I am being downvoted for asking what I believe to be a reasonable question.

> On the low end of my concern is the annoyance of constantly updating names in yaml files, and on the high end is worry that a rogue dev could deliberately add in a security hole that would compromise my secrets.

> Is there any assurance this won't happen?

This isn’t really a reasonable request. You can do any of this yourself as well, so your assurances are your own. If you want someone else to own those assurances you need to pay up.


> This isn’t really a reasonable request. You can do any of this yourself as well, so your assurances are your own. If you want someone else to own those assurances you need to pay up.

Sure it is. This is what third party security audits exist for. For example: https://www.hashicorp.com/solutions/auditing-and-compliance

This isn't unique to Hashicorp. Any organization which claims to offer secure protection should be willing to share this kind of information.

https://docs.securedrop.org/en/stable/what_is_securedrop.htm...

https://threatpost.com/openssl-security-audit-ready-to-start...

The point here is not "we pay more money and get better security." That's the kind of garbage logic the SSL CA cabal used for decades to maintain a monopoly before LetsEncrypt showed up. The question is, what is an indication that, although there is clearly some drama, that I can trust the software with my secrets? Did some of the people come to this new project from the Hashicorp security team? Could it be that the majority of changes in codebase are on the UX/UI, and not the security protocol implementation? There are plenty of ways to publish trust validation without demanding that a potential user spend hours poring through code looking for exploits.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: