vault-exfiltrate

proof-of-concept for recovering the master key from a Hashicorp Vault process (by slingamn)

Vault-exfiltrate Alternatives

Similar projects and alternatives to vault-exfiltrate

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better vault-exfiltrate alternative or higher similarity.

vault-exfiltrate reviews and mentions

Posts with mentions or reviews of vault-exfiltrate. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-03-30.
  • Show HN: EnvKey 2.0 – End-To-End Encrypted Environments (now open source)
    4 projects | news.ycombinator.com | 30 Mar 2022
    Vault attempts to protect against host compromise scenarios, but it's a very hard problem. Ultimately, in order to do anything useful, Vault deals with plaintext values in memory, and that means that yes, there are ways for an attacker to get access.

    Here's a good example: https://github.com/slingamn/vault-exfiltrate

    The Vault docs include a list of 'hardening' steps for secure production usage. These are great steps to take, but each one represents a mistake that could be made. And because the Vault process is trusted with plaintext secrets, the stakes are high. Making a mistake could lead to a compromise.

    With EnvKey, the host server is never sent secrets in plaintext. For defense in depth, we also follow best practices for hardening our networks. But I think we've seen with Okta and other incidents that despite best intentions, best efforts, and strong engineering, trusting the host server whatsoever just isn't good enough anymore.

Stats

Basic vault-exfiltrate repo stats
1
68
0.0
11 months ago

slingamn/vault-exfiltrate is an open source project licensed under Mozilla Public License 2.0 which is an OSI approved license.

The primary programming language of vault-exfiltrate is Go.


Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com