How we protect our most sensitive secrets from the most determined attackers

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • coen

  • Hey glc, FYI the GitHub repo [0] with the OS Code from Coen is not available, the url is probably broken.

    [0] https://github.com/monzo/coen

  • coen

    Root KSK Ceremony Operating ENvironment (by iana-org)

  • I should have linked to an internal page that redirected there so people didn't get a misleading 404, but the internal coen repo is only open to Monzo employees not the public because it contains some HSM specific stuff :( sorry - the public coen (which we're a fork of) is open though here https://github.com/iana-org/coen

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • kbd-audio

    🎤⌨️ Acoustic keyboard eavesdropping

  • There's some interesting attacks based on working out the sound of each key on a keyboard and then guessing keystrokes - https://github.com/ggerganov/kbd-audio

  • system-bus-radio

    Transmits AM radio on computers without radio transmitting hardware.

  • Have you gone fully paranoid and your air-gaped system is in a Faraday cage inside an anechoic chamber? Things like bus radio [1], coil whine and power fluctuations can be used (it has been shown) to exfiltrate data.

    [1] https://github.com/fulldecent/system-bus-radio

  • rke

    Rancher Kubernetes Engine (RKE), an extremely simple, lightning fast Kubernetes distribution that runs entirely within containers.

  • For the case of RKE, which I mentioned, I think they do it to have the cluster config available, but no idea why they use a configmap rather than a secret (https://github.com/rancher/rke/issues/1024 is the relevant issue)

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts