Summary

Top Articles:

  • SSH3: ssh using HTTP/3 and QUIC
  • tailscale - Private WireGuard networks made easy
  • container breakout through process.cwd trickery and leaked fds
  • Breaking SHA256: length extension attacks in practice (with Go)
  • Open-source fine-grained authorization service inspired by Google Zanzibar

container breakout through process.cwd trickery and leaked fds

Published: 2024-01-31 23:03:38

Popularity: None

Author: eyberg@users.lobste.rs (eyberg)

Keywords:

  • security
  • go
  • devops
  • Comments

    ...more

    SSH3: ssh using HTTP/3 and QUIC

    Published: 2023-12-15 21:36:19

    Popularity: 9

    Author: carlana@users.lobste.rs (carlana)

    Keywords:

  • security
  • go
  • networking
  • Comments

    ...more

    Breaking SHA256: length extension attacks in practice (with Go)

    Published: 2023-05-24 18:12:23

    Popularity: None

    Author: Zamicol@users.lobste.rs (Zamicol)

    Keywords:

  • security
  • go
  • cryptography
  • Comments

    ...more

    tailscale - Private WireGuard networks made easy

    Published: 2020-02-11 09:37:33

    Popularity: 4

    Author: ceh@users.lobste.rs (ceh)

    Keywords:

  • security
  • go
  • Comments

    ...more

    Open-source fine-grained authorization service inspired by Google Zanzibar

    Published: 2024-08-28 15:55:44

    Popularity: None

    Author: github.com by eaytin

    Keywords:

  • security
  • go
  • scaling
  • show
  • LLM Says: ""Authorization zone""

    Show HN: Permify 1.0 - Open-source fine-grained authorization service Permify was born out of our repeated struggles with authorization. Like any other piece of software, authorization starts small but as things grow scaling it becomes a real pain and begins to hinder product development processes. Ad-hoc authorization systems scattered throughout your app’s codebase are hard to manage, reason about, and iterate on as the company grows. Also you will need to have more specific access controls as things grow. Traditional approaches like RBAC is inefficient for defining granular permissions such as resource-specific, hierarchical, or context-aware permissions. Architecture is another problem, in a distributed system you’re going to need a solid plan to manage permissions between your services — all while ensuring high availability and providing low latency in access checks for sure. We’ve created an open-source project to eliminate the authorization burden for devs. It’s Permify, an Authorization-as-a-Service to help developers build and manage their authorization in a scalable, secure, and extendable manner. And last week, we released the first major version (v1.0.0) of it! Here is how Permify helps you handle authorization. - Centralize & Standardize Your Authorization: Abstract your authorization logic from your codebase and application logic to easily reason, test, and debug your authorization. Treat your authorization as a sole entity and move faster within your core development. - Build Granular Permissions For Any Case You Have: You can create granular (resource-specific, hierarchical, context aware, etc) permissions and policies using Permify’s domain specific language that is compatible with RBAC, ReBAC and ABAC. - Set Custom Authorization For Your Tenants: Set up isolated authorization logic and custom permissions for your vendors/organizations (tenants) and manage them in a single place. - Scale Your Authorization As You Wish: Achieve lightning-fast response times down to 10ms for access checks with a proven infrastructure inspired by Google Zanzibar, Google’s Consistent, Global Authorization System. Try it out and send any feedback our way! Comments

    ...more

    end