trillian
passage
trillian | passage | |
---|---|---|
9 | 14 | |
3,464 | 720 | |
0.3% | - | |
9.6 | 0.0 | |
4 days ago | 25 days ago | |
Go | Shell | |
Apache License 2.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
trillian
- Is there a good example of an open source non-trivial (DB connection, authentication, authorization, data validation, tests, etc...) Go API?
- Google's Trillian – Verifiable Data Structures
-
Key transparency: A transparent and secure way to look up public keys
Archived. Not sure when. :( I'm not sure what if anything is a decent replacement/substitute.
In the README examples I see text about what I think is Certificate Transparency. That was definitely the first thing this made me think of. There's also a lot of talk in the project about CONIKS[1], & associate research papers are about 'bringing key transparency to end users'.
The scenarios[2] are interesting, but I'm not sure fully how this project helps. They explicitly call out Upspin for encrypted storage, which was linked recently[3].
It appears to make heavy use of the Trillian cryptographically verifiable data store[4].
[1] https://www.schneier.com/blog/archives/2016/04/coniks.html
[2] https://github.com/google/keytransparency/blob/master/docs/s...
[3] https://news.ycombinator.com/item?id=31520559
[4] https://github.com/google/trillian
- Don't trust your logs! Implementing a Merkle tree for an Immutable Verifiable Log (in Go)
- GnuPG used to ask for your support to help protect online privacy
-
There's a guy who the Space Force and Defense Department are paying $250k a year to go to MIT to study Bitcoin for them, to see how they could use its ledger in the same way they use GPS to store and track accurate immutable information. He just got permission to go public with his work.
Related is Google Trillian: https://github.com/google/trillian
-
Threat Actors Now Target Docker via Container Escape Features
https://stackoverflow.com/questions/37058322/how-can-i-verif...
CT (Certificate Transparency) is another approach to validating certs wherein x.509 cert logs are written to a consistent, available blockchain (or in e.g. google/trillian, a centralized db where one party has root and backup responsibilities also with Merkle hashes for verifying data integrity). https://certificate.transparency.dev/ https://github.com/google/trillian
Does docker ever make the docker socket available over the network, over an un-firewalled port by default?
-
Tamper-Evident Logs
Yeah, right on!
We're looking in more depth at other use cases, developing a better understanding of which types of problems this might be useful for, and ways to reason about the properties you want/get from using systems like this (e.g. https://github.com/google/trillian/tree/master/docs/claimant...)
[Disclaimer: I work on CT, Trillian, and some other related projects]
passage
- GPG vs AGE, signing and encryption
-
Self-hosted Secrets Manager (or something alike)
passage
-
Age: Modern file encryption format with multiple pluggable recipients
_o/ hi all, age author here!
The OP link is the spec, here's a few other things you might find interesting
- the Go reference implementation https://age-encryption.org
- the Go library docs https://pkg.go.dev/filippo.io/age
- the CLI man page https://filippo.io/age/age.1
- an interoperable Rust implementation by @str4d https://github.com/str4d/rage
- a YubiKey plugin by @str4d https://github.com/str4d/age-plugin-yubikey
- the draft plugin protocol specification (which we should really merge) https://github.com/C2SP/C2SP/pull/5/files?short_path=07bf8cc...
- a Windows GUI by @spieglt https://github.com/spieglt/winage
- a discussion of the authentication properties of age https://words.filippo.io/dispatches/age-authentication/
- a discussion of a potential post-quantum plugin https://words.filippo.io/dispatches/post-quantum-age/
- a password-store fork that uses age instead of gpg https://github.com/FiloSottile/passage (see also: how I use it with a YubiKey https://words.filippo.io/dispatches/passage/)
-
Gnu Pass and possibly a general linux question...
https://github.com/FiloSottile/passage and https://github.com/FiloSottile/passage/issues/24
-
Bitwarden Acquires Passwordless.dev
Without looking close at your suggestion, you might want to look at passage [0] by the creator of age. It's a fork of pass [1] using age as the backend.
[0] https://github.com/FiloSottile/passage
- passage: A fork of password-store (https://www.passwordstore.org) that uses age (https://age-encryption.org) as backend.
-
age.el: age encryption support for Emacs
I wanted to reduce the amount of key management in my life to the bare minimum. I don't use gpg for its intended purpose (maintaining a web of trust with folks that you communicate with), but rather only use it for Emacs file encryption and things like password-store (which I'm replacing with https://github.com/FiloSottile/passage and will also port the Emacs pass frontend to work with).
- pass: password manager for true geeks. Control everything yourself, sync among devices, enjoy your security. Cheat sheet for setting it up
- pass – the standard Unix password manager
-
GnuPG used to ask for your support to help protect online privacy
there in fact exists a pass-like interface for age: https://github.com/FiloSottile/passage
What are some alternatives?
Proofable - General purpose proving framework for certifying digital assets to public blockchains
age-plugin-yubikey - YubiKey plugin for age
libgossamer - Public Key Infrastructure without Certificate Authorities, for WordPress and Packagist
gopass - The slightly more awesome standard unix password manager for teams
PGPy - Pretty Good Privacy for Python
django-ca - Django app providing a Certificate Authority
sops - Simple and flexible tool for managing secrets
gatekeeper - 🐊 Gatekeeper - Policy Controller for Kubernetes
tierney - Generic library for structured commands with explicit parallelism
Pass4Win - Windows version of Pass (http://www.passwordstore.org/)