Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)L
Posts
1
Comments
4
Joined
2 mo. ago

  • I agree, for serious secrets you should have something physical involved.

    I spent a bit of time exploring some mechanism to encrypt files on disk and require a yubikey press to decrypt them transparently for the process requesting access, but I didn't really come up with a solution I liked. The idea there would be you're prompted "/usr/bin/safe wants to access secret.key, but it is marked as sensitive, decrypt and allow?". The notification part would be easy with fanotify but it wasn't entirely clear to me the best way to perform the decryption. I think storing the secret on a FUSE file system could work? Things like https://github.com/rfjakob/gocryptfs come to mind

  • Right it's just for things you don't use but a credential harvester would find interesting.

    I've been working a lot on containing the blast radius with some careful LXC usage, but this was a quick way to get some real value without a ton of thought.

  • There is a very high chance there are files you will never use that a credential harvester would be interested in. For example some look for certain wallets that I definitely don't have, so I create a canary file for that. You can also add $HOME/.ssh/id_rsa and $HOME/.ssh/id_ed25519 and then use nonstandard key names for your typical key usage etc.

    I've been running this for a week now with no lost connections yet :)

  • Linux @programming.dev

    File canary kill switch

    gitlab.com /drosseau/file-canary