Live data from Hacker News

XSS Twitter in minutes; Why you shouldn't store important data with 37signals

brian.mastenbrook.net

51–60 of 61 posts

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#51
post #45
post #43

Earlier quoted context omitted.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe

Please don't call commenters on HN "douchebags".

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#52
post #38

Brian, I'm on the receiving end of security@37signals.com and @rubyonrails.org. I read your post with great dismay, to put it mildly. You're understandably pissed: we whiffed on our response to you by changing venue to Rails security without keeping you in the loop. This is my fault. I identified it as a Rails issue and requested that you forward your findings to the Rails security team so we could investigate in con…

There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…

@tptacek:

Second Google result for "apple security": http://www.apple.com/support/security/

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#53
post #52
post #38

Earlier quoted context omitted.

There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…

@tptacek: Second Google result for "apple security": http://www.apple.com/support/security/

Yes, and that's a good page. Now tell me how to navigate to it on the OS X site, and note how much security marketing fluff you'll see before you ever find it.

I don't even think Apple is a bad example of the form. I think it's entirely reasonable for them to market security on their main pages, and leave the researchers to find their support page on Google. There are tens of researchers, and millions of customers.

Apple has a lot of really smart people working in security research and software security. Some of them are friends of ours. And some of those people are frustrated with Apple for any number of reasons. But none of them --- in fact, nobody I know that works in software security --- is particularly upset about http://www.apple.com/macosx/security. It is what it is.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#54
post #45
post #43

Earlier quoted context omitted.

Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html

Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe

Regarding astroturfing: I work for Microsoft. It's no secret.

Regarding promises of a happy happy fun fun friendly new MS: I have no illusions. All I'm saying is assume incompetence, not malace. I'm also going further to say assume there are lots of smart, well intentioned people working hard on things that involve problems and complexities beyond the understanding of an engineer who has never worked on anything the scale of the Windows ecosystem.

For the record: I don't have Windows installed at home. I run Ubuntu on my desktop and Snow Leopard on my Macbook. I have an iPhone and primarily use Google web services. Hell, I was an intern at Google.

Personally, I'm at Microsoft to work on Xbox/Gaming. Among my co-workers I'm known as that guy who won't shut up about open source software, startups' web services, and Apple's great taste. You can call me culpable if you want, but I'm part of the solution, not the problem.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#55
post #47
post #34

Earlier quoted context omitted.

Hrm, interesting. I didn't know that Microsoft was leading the industry in security. If we're talking about the commercial OS market, I suppose that makes sense because you're pretty much only comparing them with Apple.

And Linux, and Solaris. And Apache. And Tomcat.

Windows security is better than Linux and BSD? I thought SELinux, TrustedBSD, and OpenBSD have windows beat.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#56
post #55
post #47

Earlier quoted context omitted.

And Linux, and Solaris. And Apache. And Tomcat.

Windows security is better than Linux and BSD? I thought SELinux, TrustedBSD, and OpenBSD have windows beat.

SELinux and TrustedBSD are probably safer than Windows. Not sure I'd go that far with OpenBSD.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#57
post #56
post #55

Earlier quoted context omitted.

Windows security is better than Linux and BSD? I thought SELinux, TrustedBSD, and OpenBSD have windows beat.

SELinux and TrustedBSD are probably safer than Windows. Not sure I'd go that far with OpenBSD.

You're the resident expert, I was just going off of the bits I know about each one. ;)

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#58
post #57
post #56

Earlier quoted context omitted.

SELinux and TrustedBSD are probably safer than Windows. Not sure I'd go that far with OpenBSD.

You're the resident expert, I was just going off of the bits I know about each one. ;)

Well, it's tough, right? SE and Trusted both have lots of kernel hardening features that Win7 doesn't have. And even base Linux and FreeBSD are "simpler" (until you add OpenSSH, Apache, and the NFS stack). Win7 has baggage; MSFT is still paying for the DCOM mistake.

You have to counter that, though, with the hundreds of thousands of dollars Microsoft spends on security testing every functional unit of the shipping product. It is not unpossible that they paid someone at Leviathan, iSEC, or IOActive to spend a week auditing Minesweeper (they haven't paid us to do that).

They don't just audit their code. A couple times a year, they do a little internal conference called "Blue Hat" (pace Black Hat), which, as the beauty pageant for all their consulting vendors, tends to get the best researchers from those firms as speakers. They highlight trends and findings for execs, and try to get some of the benefit of the audits spread across multiple projects.

There's also an entire layer of researchers, testers, and project managers on top of the security tests. Some of those people (like Leblanc and Howard) are actively turning the results into curricula for training, or for new code standards, or even changes in the shipping VC++ config. Other people develop automated testing tools. Still others develop better, more secure APIs.

When you think of the resources Google has, you assume that the best developers there all have access to a MapReduce cluster that will run their "hello world" test programs against the corpus of the entire Internet as of I dunno 3 weeks ago. Only Google has that resource. Microsoft has more ongoing security test results than any other company in the world --- even moreso because they had so. much. catching. up. to. do. from the late '90s. That has to be a killer resource for them.

So, we'll see. I wouldn't run a Microsoft OS as a server, for a lot of reasons. But I have more respect for the work they're doing --- and the intentionality of that work --- than I do for a lot of Unix security projects.

Everything OpenBSD did to fix NetBSD's security in the '90s, Microsoft adopted on a massive scale, and then spent tens of millions of dollars to improve.

Sorry for the long comment, I just don't want to come off like I'm sniping at you, or trying to start an OS war.

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#59
post #58
post #57

Earlier quoted context omitted.

You're the resident expert, I was just going off of the bits I know about each one. ;)

Well, it's tough, right? SE and Trusted both have lots of kernel hardening features that Win7 doesn't have. And even base Linux and FreeBSD are "simpler" (until you add OpenSSH, Apache, and the NFS stack). Win7 has baggage; MSFT is still paying for the DCOM mistake. You have to counter that, though, with the hundreds of thousands of dollars Microsoft spends on security testing every functional unit of the shipping pr…

Sorry for the long comment, I just don't want to come off like I'm sniping at you, or trying to start an OS war.

Actually, the long comment is much appreciated. It's a very interesting subject for me. I wasn't trying to say that I doubted you, just that I'm no expert. :)

Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals

#60
post #10

Can someone help to compile a good security policy and guideline for web apps? I guess every web app should have a page dedicated to security similar to privacy policy and terms of service. What are the essential information should go there? Special email dedicated to report security issues? PGP key to encrypt emails? and What else?

Don't trust any data that comes from outside your app (urls, querystrings, http request headers, databases, files) and you'll be right. Perl's Taint Mode enforces this automatically. Don't know if any other languages have it? http://www.webreference.com/programming/perl/taint/

IIRC, Ruby lets you set taintedness Safe Levels with the -T command-line option or setting $SAFE per thread.
Post reply on HN