Live data from Hacker News

Sops – An editor of encrypted files using AWS KMS and PGP

github.com

11–16 of 16 posts

Re: Sops – An editor of encrypted files using AWS KMS and PGP

#11
post #6

FWIW, KMS can get expensive if you're (for example) using transparent S3 encryption. Once you enable that (which is actually of dubious security value anyway), every S3 operation involves a KMS operation, which can get surprisingly substantial pretty fast. (I'm not making any comment on Sops per se - just saying to be careful around KMS,and thus Sops, for high-volume requirements.)

> (which is actually of dubious security value anyway)

FYI the value isn't necessarily in stopping AWS from maliciously reading your data if they wanted to (though it does make that slightly more difficult too), it's knowing that your data can't be easily recovered by someone who has access to the physical hard drives it's stored on. A typical scenario would be someone who knows where old drives are disposed of once they leave the data center - presumably AWS takes measures to wipe/destroy such drives, but knowing that the underlying data is encrypted at rest is extra assurance. There's also value for people whose compliance requirements dictate data is encrypted at rest regardless of cost and whether it actually makes sense to do.

Re: Sops – An editor of encrypted files using AWS KMS and PGP

#12
post #5

Earlier quoted context omitted.

We've been using sops for about a year and it's a great solution to the startup problem of having secrets but needing to store them somewhere. The other options all involve additional infrastructure, while this just uses AWS infrastructure at the free level.

For a 1Password-like hosted service that also requires no additional infrastructure, check out EnvKey - https://www.envkey.com It handles encryption keys completely behind the scenes, is trivial to integrate, and provides a UI to easily manage multiple environments and access levels in one place. There will, of course, always be a role for more DIY solutions like sops, but if your goal is to have configuration/secret…

(Full disclosure: danenania is the founder of EnvKey, as mentioned in his/her profile.)

Re: Sops – An editor of encrypted files using AWS KMS and PGP

#13

We have been using Sops for a few months, it's pretty impressive really. reading your Sops config during githooks allows you to ensure everything is encrypted before commit. The only downside I have come across is that if you accidentally encrypt a file twice you essentially lose the data. obviously, this is user error but some additional protections around this would be good.

had the same issues and now i always either check for the sops encryption keys with a sops wrapper script before encryption or decrypt to a git-ignored temp file that is immediately deleted after use.

Re: Sops – An editor of encrypted files using AWS KMS and PGP

#14
post #6

FWIW, KMS can get expensive if you're (for example) using transparent S3 encryption. Once you enable that (which is actually of dubious security value anyway), every S3 operation involves a KMS operation, which can get surprisingly substantial pretty fast. (I'm not making any comment on Sops per se - just saying to be careful around KMS,and thus Sops, for high-volume requirements.)

> (which is actually of dubious security value anyway) FYI the value isn't necessarily in stopping AWS from maliciously reading your data if they wanted to (though it does make that slightly more difficult too), it's knowing that your data can't be easily recovered by someone who has access to the physical hard drives it's stored on. A typical scenario would be someone who knows where old drives are disposed of once…

FYI :) see https://d0.awsstatic.com/whitepapers/aws-security-whitepaper... for information on the DoD/NIST protocols used to destroy the drives.

Re: Sops – An editor of encrypted files using AWS KMS and PGP

#16

Earlier quoted context omitted.

For a 1Password-like hosted service that also requires no additional infrastructure, check out EnvKey - https://www.envkey.com It handles encryption keys completely behind the scenes, is trivial to integrate, and provides a UI to easily manage multiple environments and access levels in one place. There will, of course, always be a role for more DIY solutions like sops, but if your goal is to have configuration/secret…

(Full disclosure: danenania is the founder of EnvKey, as mentioned in his/her profile.)

Indeed - sorry to leave that out!
Post reply on HN