Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cipherboy
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
OpenBao Features – Recursive Lists (Scan) & Filtering
(openbao.org)
1 points
by
cipherboy
1mo ago
|
0 comments
2.
▲
Announcing OpenBao v2.6
(openssf.org)
2 points
by
cipherboy
1mo ago
|
0 comments
3.
▲
OpenBao Features – Declarative Plugins
(openbao.org)
2 points
by
cipherboy
2mo ago
|
0 comments
4.
▲
OpenBao Features – Declarative Configuration
(openbao.org)
3 points
by
cipherboy
2mo ago
|
0 comments
5.
▲
by
cipherboy
2mo ago
Vault has had PKI since pre-v1; ACME was introduced in 2022 to modernize its APIs.
6.
▲
by
cipherboy
1y ago
I'll bite ;-) Appreciate your replies as always tptacek! It is a fair criticism. But I think two things give us an advantage here: 1. IBM started this fork and later bought HashiCorp, with the acquisition having fully completed. I'
7.
▲
by
cipherboy
1y ago
Yes and https://discuss.hashicorp.com/t/hcsec-2024-05-vault-cert-aut... was an earlier authN+authZ bypass in the same code block. So maybe one step down in severity, though I do not know the details of what HCSEC-2024-
8.
▲
by
cipherboy
1y ago
Since HashiCorp and OP did not opt to disclose to OpenBao, the most authoritative source right now is HashiCorp's security tracker, linked down-thread: https://news.ycombinator.com/item?id=44821779 https://d
9.
▲
by
cipherboy
1y ago
To quote a movie, only a Sith deals in absolutes ;-) The OpenBao community call is in 10 minutes if you want to talk more about it live: https://calendar.google.com/calendar/embed?src=s63voefhp5i9p... (OpenSSF communit
10.
▲
by
cipherboy
1y ago
OpenBao, under the Linux Foundation's OpenSSF, is making meaningful improvements to the code. I'd love to have high-quality reports, if you're willing to re-visit these. :-)
11.
▲
by
cipherboy
1y ago
I do not speak for HashiCorp, but they have published information on this CVE here: https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enu... OpenBao is reasonably confident in our fix: https://github.
12.
▲
by
cipherboy
1y ago
For anyone interested in CVE-2025-6010: https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enu...
13.
▲
by
cipherboy
1y ago
On behalf of the OpenBao project, I welcome collaboration with future researchers. We were not informed of these vulnerabilities before HashiCorp posted their usual CVE bulletins, which is disappointing. (Especially as HashiCorp's Vaul
14.
▲
by
cipherboy
1y ago
Dupe of https://news.ycombinator.com/item?id=44276916
15.
▲
by
cipherboy
1y ago
While I'm sure Vault contracts run more than what I'd care to know, the project is set up under the Linux Foundation and I've been told in the past that we as a project are capable of receiving direct donations. If you'r
16.
▲
by
cipherboy
1y ago
Not without community involvement :-) Horizontal scalability and disaster recovery is one of the next larger features on our mind. We won't use the architecture of Performance Secondaries, and likely will transparently upgrade (existin
17.
▲
by
cipherboy
1y ago
Yes, implemented from scratch by the community but (mostly--barring one reported issue) the same functionality and behavior. Not storage-level compatible, we (likely?) made different storage layout decisions that I'm rather hopeful wil
18.
▲
by
cipherboy
1y ago
You should read this RFC: https://github.com/openbao/openbao/issues/1340 If you use that with a PostgreSQL backend (which doesn't require raft and has faster leader changes), it might be possible. Feel f
19.
▲
by
cipherboy
1y ago
It is a secrets manager; I think it's a fair question. Very few individuals will want to run them, the reality is they're mostly for businesses to consume. Businesses need maintenance reliability and continuity plans and that'
20.
▲
by
cipherboy
1y ago
Definitely. It's why I've been pushing for open governance and slowly building community's trust in additional maintainers to avoid burnout and ensure continuity. You can see maintainer process here: https://github
21.
▲
by
cipherboy
1y ago
Nice! The biggest gap with Vault Enterprise that I'm hoping we'll get to next release will be horizontal scalability of read requests. We should be fairly compatible otherwise! Our helm chart just got a few more maintainers (I con
22.
▲
by
cipherboy
1y ago
AWS plugins are released separately: https://github.com/openbao/openbao-plugins/releases
23.
▲
by
cipherboy
1y ago
Yes, a big thank you to you, Jan, in particular! The organization has been slowly building trust in more committers and maintainers and so he's had to personally review many a pull request of mine in the interim. :-D
24.
▲
by
cipherboy
1y ago
If you have reproducers for behavioral differences, happy to take issues and PRs! (Entities was discussed here: https://github.com/openbao/openbao/issues/1110#issuecomment-... ) Right, check out our vision pos
25.
▲
by
cipherboy
1y ago
GitHub's charts are inaccurate and a quick glance at the commit list would tell you that: https://github.com/openbao/openbao/commits/main/ -- you have to cross some threshhold number of commits acro
26.
▲
DigiCert: Threat of legal action to stifle Bugzilla discourse
(bugzilla.mozilla.org)
6 points
by
cipherboy
2y ago
|
0 comments
27.
▲
by
cipherboy
2y ago
The combination of paginated list (last release) and transactions (this release) are a wonderful improvement over HashiCorp Vault. They're already paying dividends with the potential to implement much-requested improvements to Vault li
28.
▲
Announcing OpenBao v2.1.0 - OSI-licensed fork of HashiCorp Vault
(openbao.org)
15 points
by
cipherboy
2y ago
|
1 comments
29.
▲
ICP-Brasil: Mis-issued certificate
(bugzilla.mozilla.org)
61 points
by
cipherboy
2y ago
|
3 comments
30.
▲
OpenBao's First Roadmap and Community Direction
(openbao.org)
3 points
by
cipherboy
2y ago
|
0 comments
More ›