6 ms·
Tarsnap email confirmation bypass
- glag0lit 11y agotl;dr a friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. also, there is no bug bounties for the tarsnap website, only for tarsnap code.
- cperciva 11y agoa friendly guy reported to tarsnap that you could sign up without needing the emailed confirmation link by creating that same confirmation link yourself with the cookie/token being hidden, but present in the HTML code. That's a decent summary, but I didn't think I was all that long-winded...
- djm_ 11y agoQuite the opposite, it's nice to see someone put some effort into their write-ups. It's so much more readable as a story.
- glag0lit 11y agoOh it really is just a summary, and no commentary as to whether TFA was long-winded or not. That's left to decide for each individually.
- w8rbt 11y agoWhen you write tl;dr followed by a very short summary, doesn't that itself imply that the article was long?
- tome 11y agoThe summary was certainly shorter than the article!
- slight 11y agotl;dr has also become a general shorthand for a summary.
- simcop2387 11y agoIt's almost an abbreviation for summary!
- ninguem2 11y agoMaybe the guy who found the bug won't get $1000, according to your rules, but he definitely deserves a cookie.
- monochromatic 11y agoPlease don't turn this place into a pun-fest.
- cperciva 11y agoI did pay out a bounty of $200 for this.
- deleted 11y ago[deleted]
- junto 11y agoLesson of the day: Hidden form values are not hidden from the user, they just aren't plainly visible to the user on screen. Never "hide" sensitive data in those hidden input fields.
- caf 11y agoThe value of writing comments intended for your future self was confirmed in a strange way for me: I once found myself googling some faintly obscure question of systems programming, and soon found an article that answered my question perfectly. At that point I noticed with considerable surprise that I was reading a web archive of a Usenet posting I had made myself, some 10 years prior - of all the people to randomly run into on the Internet, your past self is one of the strangest.
- jpgvm 11y agoThis has happened to me more times than I would like heh. Makes me realise the fallibility of memory.
- NicoJuicy 11y agoI have this with stackoverflow sometimes :p
- junto 11y agoSame here. Also my old blog posts. My weirdest one was when I was searching for an answer to a progamming question and ended up finding (and then contacting) my "long lost" cousin (the name was fairly unusual). Turns out he became a programmer too.
- tome 11y agoThat's happened to me, but unfortunately I've mostly found my old questions, not my old answers!
- bentcorner 11y agoI've had this happen to me a few times, but usually it's "I've answered this before for someone else, and now I have the same question. What was my answer again?"
- annnnd 11y agoThis goes to show how useful it is to share your knowledge. You never know when you might need it back. :)
- chloeloubag 11y agothankyou x
- jballanc 11y agoThere was a paper a couple years ago out of Microsoft research (if I recall correctly), that looked at a number of vulnerabilities in OAuth as used by Facebook, Twitter, and a few others. The ah-hah moment for me, though, was that they identified these vulnerabilities by turning the usual view of a web app inside-out: instead of viewing the client/browser as one endpoint on a communications channel, they treated the browser as a de facto man-in-the-middle. For OAuth, it is responsible for passing along messages between the OAuth provider and the authentication requesting website. In the case described in this article, the browser is just a MITM for a server sending messages to itself.
- sanderjd 11y agoI haven't seen that paper, but it strikes me as being exactly the right model. A lot of vulnerabilities on the web seem to arise from the tension between the goal to require as little persistent state as possible to serve requests, and the browser as a public channel that any non-persisted state must be sent across.
- jonahx 11y agoI love writeups like this, and enjoyed the level of detail Colin provided. I take away a different lesson, though: even simple web security is easy to get wrong, even for a very smart, very talented developer. I'm not sure what the solution is, though. As for the comments, while I don't take a hard line here, I agree with Bob Martin's quote: "Every time you write a comment, you should grimace and feel the failure of your ability of expression." Wherever possible, you are better off rewriting the code and variable names to clarify in the code itself whatever you wanted to say in the comments. It's hard to say how to accomplish that here without knowing more about the code, though. And it may have been so difficult that a comment was the right choice.
- zimpenfish 11y agoCode can only tell you about the implementation - never the intent. Taking an example from my code yesterday: $config->{template} = $container->template; There's not much can be clarified here, I don't think. But it tells you precisely nothing about why it's required in this instance. (There's no spec for the file format - all have the `template` key in the `container` section but some also have it in the `config` section. Since I can't change these files, I have to deal with the duality. But you'd never be able to guess that from this code without a comment.)
- strommen 11y agoThere are definitely cases where comments are required to describe intent...the "Why?" of the code. But the problem with comments is that they'll inevitably get out of sync with the code. And a wrong comment is far worse than no comment at all. In a case like Colin's, I think something as simple as including "secure" or "secret" in the name of the variable would prevent this stuff from happening. If your variable is named `secureAccountCode` then it's unlikely you'll be silly enough to render it back to a hidden input (unless you're writing code comments for "Drunk Me" like the Disqus commenter on the article, in which case all bets are off). There's a classic Joel on Software article about this, "Making Wrong Code Look Wrong" [1] [1] http://www.joelonsoftware.com/articles/Wrong.html http://www.joelonsoftware.com/articles/Wrong.html
- paulannesley 11y ago> That last part is ultimately the most important lesson from this: Comments matter! In most cases, logically granular commits with good commit messages, and a knowledge of `git log` and `git blame` etc, is better than leaving comments. Comments can easily get out of sync with reality (see https://twitter.com/nzkoz/status/538892801941848064 https://twitter.com/nzkoz/status/538892801941848064 ) and create a lot of noise that make reading the code harder (especially when the comment and code contradict each other). I only leave brief comments where some code is necessary but at a glance doesn't look right, or has a non-obvious reason. But first I find a way to make it look right or be obvious.
- MichaelGG 11y agoComments are helpful as an overview of a module, briefly outlining what the goals and major ideas. I'm currently starting to work on a large project, all in C, heavily manually threaded, with essentially zero comments. It's open source so I can't complain, but boy does it make figuring things out difficult. Especially in C, where so much code is pushing bytes and pointers around, that there could easily be unintended functionality that might not be desired. Getting devs to write separate documentation is more difficult than comments, and is more likely to get out of sync. Better if they write some general overview inline. (On the opposite end, I also recently reviewed a project that has almost no comments, except on calls to malloc and free, with comments "get some memory" and "release memory".)
- cperciva 11y agoComments can easily get out of sync with reality This may be true, but I find that every other form of documentation becomes out of sync with reality even more easily, and/or is not in the right place to be noticed when some code is being edited.
- idlewords 11y agoI love that colin got trapped by his weirdly pedantic obsession with Canadian invoices. I hope the next bug involves picodollars.
- cperciva 11y agoWhat you call a "weirdly pedantic obsession" is me trying to not break the law.
- nchelluri 11y agoDoes he mean "token" instead of "cookie"?
- cperciva 11y agoA token is something you are given so that you can give to someone else. A cookie is a token where the "someone else" is the person who originally gave it to you. I meant cookie.
- nchelluri 11y ago> it sends that cookie to you as part of a URL in the confirmation email This certainly isn't a web cookie in the sense that I'm used to (a cookie would be a part of the HTTP header, and you can't specify that header in a URL). It is more like a token as I understand it. Maybe what you are describing is how the web cookie term was started (based on the behavior of generating a thing that someone else gives back to you) but it doesn't sound like a cookie at all to me.
- cperciva 11y agoYes, HTTP cookies are so named because they're... well, cookies. The concept is more general and was around long before HTTP though.