Comment by brendoelfrendo
4 hours ago
I mean, they do happily explain the TailScale features that you can use to avoid this kind of issue, but the general advice of "don't leave long-lived keys lying around where they're accessible, do anything except for that" is pretty generic, good advice.
You always need a long-lived key somewhere. Keeping it in an HSM is probably the safest, but also pretty expensive.
Suppose someone could break RSA / Elliptic Curve Crypto, mathematically (because the hardness assumptions were flawed).
This person doesn't need to store the private keys, and has the luxury to recompute them on the fly when needed!
Yes, you'll probably need to buy a specific tool or product to have secure key storage. If you're running infrastructure that requires long-lived secrets, then you either need to have a place to keep them and a plan for secrets lifecycle management, or you need to accept the risk that those secrets could be compromised.