I'm usually the first person here to jump to 37s' defense. I know some of their people, they're hometown heroes, and I use and like their products. This is hard to defend, guys. It is literally the-simplest-thing-not-to-fuck-up. Nobody's asking you not to have security vulnerabilities. In fact: nobody's even asking you to fix vulnerabilities. We just need a reliable way to communicate with you about them. If you're s…
XSS Twitter in minutes; Why you shouldn't store important data with 37signals
41–50 of 61 posts
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#42On one hand, they're pretty much "our way or the high way" about any support concerns/feature requests.
But, once caught out in public about any issue, they're all over it.
I suggest a very strong dose of self-administered humility for their founders would go a long way. That doesn't mean being un-opinionated; it just means being realistic about human nature and its vagaries as it applies to themselves.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#43Earlier quoted context omitted.
That's because Microsoft is good at anything that they throw resources at. Unfortunately, we haven't thrown enough resources at determining what to throw resources at.
Here's a hint: throw resources at supporting web standards in internet explorer. Seriously that is the main reason I hate Microsoft and around here I'd wager I'm far from alone. IE's fuckedness is inexcusable . If you actually fixed it, 90% of the reasons I hate Microsoft would just melt away that instant. And until you fix IE, it's just "DOS Ain't Done til Lotus Won't Run", Web Edition, as far as I'm concerned.
A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#44Brian, I'm on the receiving end of security@37signals.com and @rubyonrails.org. I read your post with great dismay, to put it mildly. You're understandably pissed: we whiffed on our response to you by changing venue to Rails security without keeping you in the loop. This is my fault. I identified it as a Rails issue and requested that you forward your findings to the Rails security team so we could investigate in con…
There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…
We will make this right.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#45Earlier quoted context omitted.
Here's a hint: throw resources at supporting web standards in internet explorer. Seriously that is the main reason I hate Microsoft and around here I'd wager I'm far from alone. IE's fuckedness is inexcusable . If you actually fixed it, 90% of the reasons I hate Microsoft would just melt away that instant. And until you fix IE, it's just "DOS Ain't Done til Lotus Won't Run", Web Edition, as far as I'm concerned.
Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html
Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable.
Gee, can you feel the love in my comments? Hehe
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#46Earlier quoted context omitted.
Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html
Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe
everyone who works for them is culpable
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#47Earlier quoted context omitted.
Where by "decent" we mean "leads the industry in". =)
Hrm, interesting. I didn't know that Microsoft was leading the industry in security. If we're talking about the commercial OS market, I suppose that makes sense because you're pretty much only comparing them with Apple.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#48Earlier quoted context omitted.
Well, Microsoft has no strategic interest in helping the web, as that would interfere with their desktop products. This is well established. IE was just a big Trojan to slow (yes, slow) and mess the Web world. A reference, just off the top of my head, is Spolsky's API War: http://www.joelonsoftware.com/articles/APIWar.html
Well, yeah, obviously. And the trojan is still doing damage. Which is why I can't take astroturfing douchebag shills like snprbob86 et al and their promises of a happy happy fun fun friendly new MS seriously. A leopard can't change its spots. And until I see IE change - MS is the worst company in tech and everyone who works for them is culpable. Gee, can you feel the love in my comments? Hehe
Hint: If you know a person is a Microsoft employee (as I am, FYI), it's not astroturfing. It's not that hard, kids.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#49Brian, I'm on the receiving end of security@37signals.com and @rubyonrails.org. I read your post with great dismay, to put it mildly. You're understandably pissed: we whiffed on our response to you by changing venue to Rails security without keeping you in the loop. This is my fault. I identified it as a Rails issue and requested that you forward your findings to the Rails security team so we could investigate in con…
There are still a couple of issues Brian brought up you haven't addressed. The main one being the hubris of the copy on your security page. Declaring users data to be uncompromisable then justifying this by listing mostly physical restrictions to the datacenter seems to ignore rather the larger security issues for web-based applications. A firewall and latest security patches do not make one immune. His other peeve s…
Compare their security page to:
* http://www.salesforce.com/company/security.jsp
* https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/Marketing/g...
* http://www.apple.com/macosx/security/ (heh)
* http://www.webex.com/pdf/wp_security_overview.pdf
* http://www.netsuite.com/portal/infrastructure/main.shtml
Don't ask 37s to meet a standard that nobody else meets. It's just muddying the real issue, which they're clearly trying to address.
This comment, btw, isn't about 37s. It's about the singularly bad advice that web startups should have a fully-transparent conservative "security" page that talks about cross-site scripting and CSRF attacks, when their competitors have pages about "state of the art firewall security". To normal people (ie, customers), the "state of the art firewall security" people sound like they know what they're doing.
Re: XSS Twitter in minutes; Why you shouldn't store important data with 37signals
#50I think what we've really learned from this is that the current JavaScript security model is not good for what people are using the web for these days. We really need something like a " " block, where anything inside could never use JavaScript (including links that are to javascript: URLs). This would make life a lot easier for web developers.
It's probably better to disable the JavaScript engine based on certain heuristics, for instance when there is invalid character encoding in attributes.