Ruby gems are still not safe to use
cristianobetta.com
Ruby gems are still not safe to use
1–10 of 45 posts
Re: Ruby gems are still not safe to use
#2Re: Ruby gems are still not safe to use
#3- this is a real issue. I've used rpm shell execution to modify sshd as well as other system components in order "install" additional software. http://web.archive.org/web/20090211040821/http://www.idle-ha...
as you can see from that archived post, it's very important to have trust of what you are installing. especially when you have to install with root permissions....
Seeing how many references exist to "sudo gem install blah"... this is very serious as it's a high reward if you're able to get your remote code executing with root privileges (assuming as most would not limit sudo access e.g. user ALL=(ALL) ALL )...
Re: Ruby gems are still not safe to use
#4"Stop running code on gem install." - this is a real issue. I've used rpm shell execution to modify sshd as well as other system components in order "install" additional software. http://web.archive.org/web/20090211040821/http://www.idle-ha... as you can see from that archived post, it's very important to have trust of what you are installing. especially when you have to install with root permissions.... Seeing how m…
Re: Ruby gems are still not safe to use
#5Re: Ruby gems are still not safe to use
#6"Stop running code on gem install." - this is a real issue. I've used rpm shell execution to modify sshd as well as other system components in order "install" additional software. http://web.archive.org/web/20090211040821/http://www.idle-ha... as you can see from that archived post, it's very important to have trust of what you are installing. especially when you have to install with root permissions.... Seeing how m…
The real problem is executable code. Building C extensions typically require invoking arbitrary commands. The problem is also not unique to RubyGems: RPMs and DEB packages have preinstall and postinstall scripts, and they require root privileges.
I think a good solution would be to to run C extension compilation code as a sandboxed non-root user. If a RubyGem is being installed as a normal user, the compilation code should still be run as a separate, sandboxed user, to prevent it from messing with the user's home directory. Any build products that the compilation process generates will be copied over the destination directory. The sandbox user's home directory would be wiped after every installation.
This would severely limit the C extension building system's power (they can't generate files outside the gem directory etc without being wiped) but I think that's acceptable. Use cases that require more power can rely on external user-invoked commands, e.g. passenger-install-apache2-module.
Re: Ruby gems are still not safe to use
#7"Stop running code on gem install." - this is a real issue. I've used rpm shell execution to modify sshd as well as other system components in order "install" additional software. http://web.archive.org/web/20090211040821/http://www.idle-ha... as you can see from that archived post, it's very important to have trust of what you are installing. especially when you have to install with root permissions.... Seeing how m…
I don't see the big gain in stopping to run code on install. By definition, we install gems to run code. If we don't trust the gem author not to mess with our system on install, how can we trust him not to mess with our system when we use the gem? Granted, there might be some people that install gems as root and run them as unprivileged user only, but even as a non-root user it's a problem to run code you don't trust…
What we should have instead is a good signing infrastructure to detect when trusted gems have been tampered by a third party.
Re: Ruby gems are still not safe to use
#8"Stop running code on gem install." - this is a real issue. I've used rpm shell execution to modify sshd as well as other system components in order "install" additional software. http://web.archive.org/web/20090211040821/http://www.idle-ha... as you can see from that archived post, it's very important to have trust of what you are installing. especially when you have to install with root permissions.... Seeing how m…
I don't see the big gain in stopping to run code on install. By definition, we install gems to run code. If we don't trust the gem author not to mess with our system on install, how can we trust him not to mess with our system when we use the gem? Granted, there might be some people that install gems as root and run them as unprivileged user only, but even as a non-root user it's a problem to run code you don't trust…
Re: Ruby gems are still not safe to use
#9Then y many are giving lot of hype?