Settings

Theme

Masked namespace vulnerability in Temporal

depthfirst.com

32 points by bmit 2 months ago · 4 comments

Reader

haneul 2 months ago

Even in a product as technically wonderful as Temporal, we can have relatively simple oversights like this that lead to cross tenant leakage.

If anyone is more familiar with Temporal, is there a way clients could have had internal defense in depth that guards against tenant leakage at the provider (Temporal) level?

  • jiggunjer 2 months ago

    Don't use namespaces. Wire up multi-tenant at the RBAC level. Need stronger isolation? Run another cluster.

  • UltraSane 2 months ago

    Encrypting tenant data with per tenant keys is a good defense against this kind of thing.

  • bdj108 2 months ago

    Things like this are inevitable, especially these days.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection