Encrypt traffic between firefly and database #2

Open
opened 2021-08-11 08:24:50 +00:00 by knoflook · 3 comments
Owner

As can be seen here:
coop-cloud/organising#114

As can be seen here: https://git.coopcloud.tech/coop-cloud/organising/issues/114
Owner

Unless you have worries that your in-stack containers can be addressed publicly, then this is probably overkill? We're not doing this with any other apps fwiw. Open to reasoning to change that but that's where we're at now.

Unless you have worries that your in-stack containers can be addressed publicly, then this is probably overkill? We're not doing this with any other apps fwiw. Open to reasoning to change that but that's where we're at now.
Author
Owner

My understanding of docker networking is extremely basic but from what I understand you can sniff trafic on internal networks by performing some kind of ARP spoofing. While it's a highly improbable scenario, preventing it shouldn't be too difficult.
Here's a 52 page pdf about attacking containers that I skimmed over, saw C snippets and immediately closed: https://www.nccgroup.com/globalassets/our-research/us/whitepapers/2016/june/abusing-privileged-and-unprivileged-linux-containers.pdf

My understanding of docker networking is extremely basic but from what I understand you can sniff trafic on internal networks by performing some kind of ARP spoofing. While it's a highly improbable scenario, preventing it shouldn't be too difficult. Here's a 52 page pdf about attacking containers that I skimmed over, saw C snippets and immediately closed: https://www.nccgroup.com/globalassets/our-research/us/whitepapers/2016/june/abusing-privileged-and-unprivileged-linux-containers.pdf
Author
Owner

Also I think it's better to talk about it in here
coop-cloud/organising#114

Also I think it's better to talk about it in here https://git.coopcloud.tech/coop-cloud/organising/issues/114
Sign in to join this conversation.
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: coop-cloud/firefly-iii#2
No description provided.