Hacker News new | past | comments | ask | show | jobs | submit login

The problem is it's gonna be a golden key system where everyone who's worked there for the last ten years has a copy



That is correct. But it is possible to design a system with short lived auth tokens/keys and frequent key rotation. I designed such a system at $oldjob for remote access (see [1]). Obviously there is always a risk, and there are always syseng/ops people with access. That is correct.

[1] https://blog.heckel.io/2019/11/19/providing-remote-access-to...


Nice write up and a lot of gotchas you encountered




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: