Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review whether we should migrate from age on sops #61

Open
Kreyren opened this issue Jun 17, 2024 · 2 comments
Open

Review whether we should migrate from age on sops #61

Kreyren opened this issue Jun 17, 2024 · 2 comments
Assignees
Milestone

Comments

@Kreyren
Copy link
Member

Kreyren commented Jun 17, 2024

Refer to matrix-org/matrix-spec#975 (comment) and FiloSottile/age#578 for rationale.

To me trustworthiness and confidence is everything in open-source and i can't in good faith say that i trust the author of age, this decision shouldn't be based on feelings alone, but we should review whether sops is a better alternative on a technical level and address Post-Quantum Safety ("PQS"). Until PQS is managed we should treat our secrets as likely to be exposed in the future and adjust our threat model to not include secrets that we are not comfortable being exposed e.g. SSH keys and onion URLs with management to rotate them on demand.

Mic92, the creator of sops-nix appears to be well informed on the subject of PQS and suggest good practice: Mic92/sops-nix#451 (comment)

GnuPG a supported alternative to age in sops-nix reviewed the problem of PQS in 2014 -- https://lists.gnupg.org/pipermail/gnupg-users/2014-May/049722.html and treats it as a serious problem

Submitted an issue about HNDL in sops to get more data for the decision getsops/sops#1536

A community member made patches to implement PQS in age in their branch FiloSottile/age@main...qnfm:age:main the implementation is outdated and not finished, but it might be a good idea to utilize.

@Kreyren Kreyren added this to the Current Run milestone Jun 17, 2024
@Kreyren Kreyren self-assigned this Jun 17, 2024
@Kreyren
Copy link
Member Author

Kreyren commented Jun 19, 2024

CC @JosiahBSharkey In FiloSottile/age#231 (comment) you said that age has a post quantum age plugins can you elaborate on that? I am trying to make this infra PQS.

Thanks for anything relevant!

EDIT: Found the plugin https://github.com/keisentraut/age-plugin-sntrup761x25519

@JosiahBSharkey
Copy link

JosiahBSharkey commented Jun 19, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants