Live data from Hacker News

Viewing profile — neo2006

neo2006

HN member
Joined
Sun, Feb 08, 2015, 4:40 PM UTC
HN karma
286
Public activity
109 items

About neo2006

software engineer, golang developer, distributed systems specialist

Recent public activity

  1. comment
    Comment #47975191

    This is, for the time being, mostly an experiment. I was able to get consistent results where a diverse community of agents could provide a more accurate answers for tasks that the…

  2. story
  3. comment
    Comment #47915707

    yes I agree and we actually already do that for TLS when rewriting secrets after encryption but my point is about the fact in our threat model we consider the app as an adversary s…

  4. comment
    Comment #47911140

    Actually we have 2 applications along those boundaries you described. a webhook app that manage kubernetes manifest and another to inject the ebpf code and manage the ebpf maps. Th…

  5. comment
    Comment #47910727

    Thank you! We are planning to integrate with external secret operators, like AWS secret manager or Openboa/Vault so users can benefit from an end to end secrets protection. secret …

  6. comment
    Comment #47909885

    Thank you! I agree, each architecture have its pro and cons. If an egress gateway is available and can handle secrets it's definitely a viable solution.

  7. comment
    Comment #47905861

    I'm not super familiar with TPUs and Trusted execution environments but my understanding is that it serve a different threat model. TEE aim to protect a certain workload from the h…

  8. comment
    Comment #47905717

    For egress proxy the app need to: - send traffic to the proxy (either in a non transparent way or using routes or even ebpf to redirect traffic to the proxy transparently) - trust …

  9. comment
    Comment #47905498

    This is not something we support currently. We will need to do some research on ways to support it. The main hurdle is that we can't rewrite secrets in any of the user buffers as t…

  10. comment
    Comment #47905442

    The way we thought about it is from the lense of 2 personas: - a persona that control the control plain side, what secret to distribute to which user and what hosts they are allowe…

  11. comment
    Comment #47905420

    yes please open an issue on https://github.com/spinningfactory/kloak/issues and we can discuss this. I'm not familiar with secretless-broker but we can definitely see if that use c…

  12. comment
    Comment #47905395

    Thank you for the feedback! We are currently shorthanded so we relied on AI a lot for writing our docs, we reviewed that doc as much as we could but definitely there is room for im…

  13. comment
    Comment #47905178

    The main threat model is application leaking secrets: - Internet facing app that could potentially be hacked and bad actor exfiltrating secrets - AI agent that can exfiltrate secre…

  14. comment
    Comment #47905057

    It was not intended! We were trying to make it sound like a cloak with a kubernetes K but I guess this explanation actually checkout better!

  15. comment
    Comment #47905036

    Thank you! We will reachout and see what can be done

  16. comment
    Comment #47905030

    yes, that's right!

  17. comment
    Comment #47904584

    Thank you! Not really, the controller is not doing dataplane per-say, it only pushes eBPF programs to the kernel for the relevant apps/cgroups so that could be considered control-p…

  18. comment
    Comment #47904487

    Thank you! We appreciate your enthusiasm! :-) From technology perspective nothing prevent kloak to do rewrite on any workload scheduler or even without a scheduler (native Linux). …

  19. comment
    Comment #47904463

    Secrets are detected before encryption in the user buffer but rewrites happen post encryption in the kernel buffer to be sent on the wire. packets boundaries are not an issue becau…

  20. comment
    Comment #47904374

    I guess we are the secrets sewers then! :D We would love to hear what you think about it beyond the name though.

  21. comment
    Comment #47903852

    Hey, we're the spinning-factory team, the folks behind Kloak. Kloak runs as a Kubernetes controller. It swaps the secrets in your workloads for harmless placeholders we call kloake…

  22. comment
  23. story
  24. story
  25. comment
    Comment #45268586

    it's not a war Netanyahu is killing innocent people and taking a full population hostage. Also, most of the people in Gaza are not Hamas members and are regular civilians. What Nat…