Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"As Vault is run within our internal network (and for other reasons), TLS is disabled. "

No. No. No. No. No. No. This should NEVER be an option. You should not allow data to pass unencrypted over the wire, period.



SG Operations member here.

We're extremely aware that this isn't ideal, and is more or less the first thing we're working on fixing. It's why we have this listed both under "Causes for Concern" and "Strategic Improvements". The order of those issues isn't done so by importance :)


C.f. the NSA tapping Google's and Yahoo's internal networks since the data passed in plain text. [0]

[0] https://www.washingtonpost.com/world/national-security/nsa-i...


Theory: ALWAYS Encrypt. No exception. Don't let software go into production if it's not.

Practise: Always encrypt. Aw wait... what do you mean "tls is not supported?" Are you saying that half of our applications have been running on bare HTTP for years?. Mehhhh. Well, all our public accessible websites are running on HTTPS, right? Right. Guess it's only half a disaster after all:(


You don't know anything about their internal network.

TLS is not the only game in town.


Thank you for doing this before I had a chance to!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: