!UUqahLbShAYkkrXmKs:matrix.org

DevOS

34 Members
Seeking help and geeking out together on https://github.com/divnix/devos & https://github.com/divnix/digga10 Servers

Load older messages


SenderMessageTime
25 Oct 2021
@blaggacao:matrix.orgDavid Arnold (blaggacao) openssh-dev being used quasi-ubiquitously. 18:40:00
@blaggacao:matrix.orgDavid Arnold (blaggacao)So short lived identities have generally poor aplication support.18:40:28
@blaggacao:matrix.orgDavid Arnold (blaggacao)* So short lived identities have generally poor application support.18:41:56
@timdeh:matrix.org@timdeh:matrix.orghow does this play into nix though?18:42:30
@blaggacao:matrix.orgDavid Arnold (blaggacao) Current solution: SIGHUP as it seems and accept the downtime. 18:42:38
@timdeh:matrix.org@timdeh:matrix.orgor rather, how would it interface with nix?18:42:48
@blaggacao:matrix.orgDavid Arnold (blaggacao)
In reply to @timdeh:matrix.org
how does this play into nix though?
We don't have to care about secrets at all.
18:42:54
@blaggacao:matrix.orgDavid Arnold (blaggacao) Since nix probably never is going to be a long-running attestor. 18:43:20
@blaggacao:matrix.orgDavid Arnold (blaggacao)* We don't have to care about secrets at all (in theory).18:43:38
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Since `nix` probably never is going to be a long-running, stateful attestor that processes runtime fingerprints.18:44:16
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Since `nix` probably never is going to be a long-running, stateful attestor that processes runtime workload identity fingerprints.18:44:38
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Since `nix` probably never is going to be a long-running, stateful attestor that processes runtime workload identity fingerprints against an identity registry.18:44:56
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Since `nix` probably never is going to be a long-running, stateful attestor that processes runtime workload identity fingerprints against an identity directory.18:45:11
@blaggacao:matrix.orgDavid Arnold (blaggacao) We can manage the identity directory with nix-json, though 18:46:18
@blaggacao:matrix.orgDavid Arnold (blaggacao)* We can manage the identity directory gitopsy with `nix-json`, though 18:46:28
@blaggacao:matrix.orgDavid Arnold (blaggacao) Maybe ensure that the attetor and nix use interoperavle bin-hashing mechanisms. 18:47:09
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Maybe ensure that the attestor and `nix` use interoperable bin-hashing mechanisms.18:47:20
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Maybe ensure that the workload attestor and `nix` use interoperable bin-hashing mechanisms.18:47:49
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Maybe ensure that the workload attestor and `nix` use interoperable bin-hashing mechanisms so it's easier to upadte that witness automatically during build.18:48:47
@blaggacao:matrix.orgDavid Arnold (blaggacao)* Maybe ensure that the workload attestor and `nix` use interoperable bin-hashing mechanisms so it's easier to update that particular datapoint witness automatically during build.18:49:18
@blaggacao:matrix.orgDavid Arnold (blaggacao) Well, I'd at least conclude: we should not investigate the secrets-management category further for nix, since "secrets-management" is a fundamentally outdated answer to the identity problem. 18:51:59
@blaggacao:matrix.orgDavid Arnold (blaggacao)Everything else are just work-arounds.18:52:08
@timdeh:matrix.org@timdeh:matrix.orgeven if that's true, there are legacy reasons to improve the "secrets management" usecase18:52:45
@blaggacao:matrix.orgDavid Arnold (blaggacao)The root solution is: different answer.18:52:55
@blaggacao:matrix.orgDavid Arnold (blaggacao)* The root solution is: a different answer.18:53:08
@timdeh:matrix.org@timdeh:matrix.orgyour solution sounds fancy but also complicated, so I'm having a hard time imagining it in every case18:53:21
@timdeh:matrix.org@timdeh:matrix.orgmaybe a concrete example would help?18:53:35
@blaggacao:matrix.orgDavid Arnold (blaggacao)I think there is one fundamental realization to it, namely that knowledge is an inefficient proxy for proving an identity.18:54:22
@blaggacao:matrix.orgDavid Arnold (blaggacao)And it has always been.18:54:35
@timdeh:matrix.org@timdeh:matrix.orgyou don't think knowledge of my DNA could help prove who I am?18:54:53

Show newer messages


Back to Room ListRoom Version: 6