Live data from Hacker News

Confidant: an open-source secret management service

eng.lyft.com

1–10 of 71 posts

Re: Confidant: an open-source secret management service

#7
post #5

"KMS provides access to master encryption keys,... but doesn’t provide direct access to the master key itself, so it can’t be stolen." Doesn't Amazon KMS have access to the master key? And therefore, it can be stolen from them?

https://aws.amazon.com/kms/faqs/

"AWS KMS is designed so that no one has access to your master keys."

Re: Confidant: an open-source secret management service

#8

We use ZeroTier to encrypt our AWS microservices traffic. Way easier to setup and just ... works.

This is a bit different from network encryption (which is really valuable). This is a centralized location for services to store and retrieve secrets, like passwords to external services, SSL keys, etc..
Post reply on HN