Hacker News new | ask | show | jobs
by gaadd33 4109 days ago
Has Conjur been audited by a third party or is the source open at all? Otherwise we just have to trust that the thing that we store all of our secrets in is secure right?
1 comments

We have been audited by a 3rd party and incorporated all of their suggestions in the latest 4.4 release.

http://blog.conjur.net/conjur-4-4-released

One of their stipulations for the audit was that we don't use it for promotional purposes so I guess a NDA is required to discuss details.

The tech we use for encryption of secrets is definitely open source here: https://github.com/conjurinc/slosilo

Conjur isn't built on in-house cryptographic software - it uses trusted open-source tools - OpenSSL, PAM and so on.

Most of our work is open-source https://github.com/conjurinc https://github.com/conjur-cookbooks