Live data from Hacker News

XSS Twitter in minutes; Why you shouldn't store important data with 37signals

brian.mastenbrook.net

41–50 of 61 posts

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#41
post #18

I'm usually the first person here to jump to 37s' defense. I know some of their people, they're hometown heroes, and I use and like their products. This is hard to defend, guys. It is literally the-simplest-thing-not-to-fuck-up. Nobody's asking you not to have security vulnerabilities. In fact: nobody's even asking you to fix vulnerabilities. We just need a reliable way to communicate with you about them. If you're s…

You're exactly right, Tom. We dropped the ball on having the security@37signals.com account setup before this issue so reports went to our normal support team. A specific email address with an associated GPG key has since been added to our security page and there is a person who is tasked to respond. This was added on August 23rd when the problems with the process around the previous XSS problem were discovered.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#42
Funny, but I've always thought the 37signals team was bipolar.

On one hand, they're pretty much "our way or the high way" about any support concerns/feature requests.

But, once caught out in public about any issue, they're all over it.

I suggest a very strong dose of self-administered humility for their founders would go a long way. That doesn't mean being un-opinionated; it just means being realistic about human nature and its vagaries as it applies to themselves.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#43
post #40

Earlier quoted context omitted.

That's because Microsoft is good at anything that they throw resources at. Unfortunately, we haven't thrown enough resources at determining what to throw resources at.

Here's a hint: throw resources at supporting web standards in internet explorer. Seriously that is the main reason I hate Microsoft and around here I'd wager I'm far from alone. IE's fuckedness is inexcusable . If you actually fixed it, 90% of the reasons I hate Microsoft would just melt away that instant. And until you fix IE, it's just "DOS Ain't Done til Lotus Won't Run", Web Edition, as far as I'm concerned.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world.

A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#44
post #38

Brian, I'm on the receiving end of security@37signals.com and @rubyonrails.org. I read your post with great dismay, to put it mildly. You're understandably pissed: we whiffed on our response to you by changing venue to Rails security without keeping you in the loop. This is my fault. I identified it as a Rails issue and requested that you forward your findings to the Rails security team so we could investigate in con…

There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…

I can assure you we're looking into this entire busted chain of communications. The way this was handled (by us) was completely unacceptable. I am not a happy man this morning.

We will make this right.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#45
post #43
post #40

Earlier quoted context omitted.

Here's a hint: throw resources at supporting web standards in internet explorer. Seriously that is the main reason I hate Microsoft and around here I'd wager I'm far from alone. IE's fuckedness is inexcusable . If you actually fixed it, 90% of the reasons I hate Microsoft would just melt away that instant. And until you fix IE, it's just "DOS Ain't Done til Lotus Won't Run", Web Edition, as far as I'm concerned.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Well, yeah, obviously. And the trojan is still doing damage.

Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable.

Gee, can you feel the love in my comments? Hehe

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#46
post #45
post #43

Earlier quoted context omitted.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe

Despite the somewhat inflammatory ad hominem remark (I had to look up "astroturfing".. yay urbandictionary), I do agree with what is likely a controversial sentiment:

everyone who works for them is culpable

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#47
post #34
post #19

Earlier quoted context omitted.

Where by "decent" we mean "leads the industry in". =)

Hrm, interesting. I didn't know that Microsoft was leading the industry in security. If we're talking about the commercial OS market, I suppose that makes sense because you're pretty much only comparing them with Apple.

And Linux, and Solaris. And Apache. And Tomcat.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#48
post #45
post #43

Earlier quoted context omitted.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe

Sigh. Yet another person who seems to entirely misunderstand the concept of astroturfing.

Hint: If you know a person is a Microsoft employee (as I am, FYI), it's not astroturfing. It's not that hard, kids.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#49
post #38

Brian, I'm on the receiving end of security@37signals.com and @rubyonrails.org. I read your post with great dismay, to put it mildly. You're understandably pissed: we whiffed on our response to you by changing venue to Rails security without keeping you in the loop. This is my fault. I identified it as a Rails issue and requested that you forward your findings to the Rails security team so we could investigate in con…

There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…

He addressed your second point, and your first point isn't reasonable. Product "security" pages don't need to read like SEC disclosures.

Compare their security page to:

* http://www.salesforce.com/company/security.jsp

* https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/Marketing/g...

* http://www.apple.com/macosx/security/ (heh)

* http://www.webex.com/pdf/wp_security_overview.pdf

* http://www.netsuite.com/portal/infrastructure/main.shtml

Don't ask 37s to meet a standard that nobody else meets. It's just muddying the real issue, which they're clearly trying to address.

This comment, btw, isn't about 37s. It's about the singularly bad advice that web startups should have a fully-transparent conservative "security" page that talks about cross-site scripting and CSRF attacks, when their competitors have pages about "state of the art firewall security". To normal people (ie, customers), the "state of the art firewall security" people sound like they know what they're doing.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#50
post #29

I think what we've really learned from this is that the current JavaScript security model is not good for what people are using the web for these days. We really need something like a " " block, where anything inside could never use JavaScript (including links that are to javascript: URLs). This would make life a lot easier for web developers.

It's probably better to disable the JavaScript engine based on certain heuristics, for instance when there is invalid character encoding in attributes.

That won't work, because too much "safe" user-controlled content will contain invalid utf8.
Post reply on HN