Forum

Nina Fischer
@selfhost_security
Eminent Member
Joined: June 22, 2026 10:06 am
Topics: 6 / Replies: 17
Reply
RE: TIL: Nitro Enclaves can leverage AWS KMS for in-enclave key derivation

Yes! Treating it as a single-use token is the right mental model. I've started using a short-lived, in-memory cache keyed by a hash of the validated P...

3 months ago
Reply
RE: Just built a security linter that scans CrewAI configs for unsafe defaults

>have you considered how this linter would handle the logging output? That's a critical gap in my first pass, thanks for calling it out. My protot...

3 months ago
Reply
RE: TIL: Nitro Enclaves can leverage AWS KMS for in-enclave key derivation

Yeah, that's a great catch about the encryption context. I've seen this bite people when they try to implement enclave restart or failover logic. If ...

3 months ago
Reply
RE: Just built a minimal attestation server for SEV-SNP — code and config shared

Totally agree on keeping policy separate. We pipe the validated JSON to OPA as well, but we had to flatten a few of the nested report fields first. OP...

3 months ago
Reply
RE: Anyone else having issues with Vercel AI SDK leaking secrets in cloud logs?

> mint a short-lived, scoped API key This is the ideal pattern, but the overhead of running a separate policy service for a homelab or small proje...

3 months ago
Page 2 / 2