What is the threat model you want to mitigate using encryption at rest? Is it that a physical disk is not properly wiped after usage? Then you could just use luks and store the key anywhere else, e.g. another machine or an external volume…
OIDC is newer and many of the issues with SAML were addressed in the architecture. However I’m curious to hear which attack vectors you are thinking about.
OIDC is better when using the authorization code flow because it does not only rely on cryptography while validating the token. The relying party needs to talk to the IdP. This is better from a security perspective, because past vulnerabilities have shown, that implementing the cryptography right in every relying party is challenging. You can achieve similar security with SAML when using the artifact binding.
Note: I work professionally with Keycloak and also offer reviews of OIDC and SAML implementations.
Interesting read. I have just setup a very similar cluster this week: 3 node bare metal cluster in a 10G mesh network. Decided for Debian, RKE2, Calico and Longhorn. Encryption is done using LUKS FDE. For Load Balancing I am using the HCloud Load Balancer (in TCP mode).
At first I had some problems with the mesh network as the CNI would only bind to a single interface. Finally solved it using a bridge, veth and isolated ports.
Software development is easy, maintenance is challenging. When your system integrates with other systems and you want to make changes, it's critical to understand the details. I doubt people without IT background should be in charge of such processes.
I drive a 2023 ID.5 for 2 months and I have not faced many issues yet. Yes, the touch interface could be a bit more responsive, but I am overall very happy with the driving experience.
I have fructose malabsorption and when I eat or drink too much of it, I get brain fog (slow reaction, dizziness etc.) for one or two days. Would be interesting to see if fructose malabsorption and Alzheimer's correlate.
I think we also have lazy evaluation, heuristics (wave-particle duality), out-of-memory killers (black holes, hawking radiation) and bandwidth limitations (speed of light).
It seems obvious, hopefully it's not going to kernel panic!
Isn't that what conferences and journals are for? Reviewing and selecting the most important papers?
When something is really solved (a solution exists without negative side-effects; and this fact has been verified several times), they should indeed look for new problems.
I have not looked at kitemaker yet, but we are in the same situation. On premise Jira will have to be replaced by something else. Cloud is not option due to privacy/security/compliance reasons.
I don't know exactly. There has to be enough liquidity in Bitcoin locally to find enough persons to trade with. Starting a new cryptocurrency in such a situation will be difficult because of deflation. Deflation is extremely dangerous for the economy.
The rising of Bitcoin can be a threat to working democracies - at least if it is used as a currency. Monetary politics are important for our society to function properly. On the other hand: For broken countries, it can help the people as a temporary replacement.
How does Ory compare to alternatives like e.g. Keycloak and Authelia?
From experience, can anyone make a recommendation for a system that can be rolled out to an organization with confidence (long-term support, security, performance)?