4 ms·
The only reason I still use Github is because of the network effect. If they fall apart, I'll migrate to a self-hosted Gitlab instance and that will be the end
by sarciszewski 11y ago
The only reason I still use Github is because of the network effect. If they fall apart, I'll migrate to a self-hosted Gitlab instance and that will be the end of that.
I'm just hoping that, should GH fail, it hold off on failing until I learn Ruby sufficiently well to review the entire GL code base so I can deploy it with confidence.
EDIT: Yes, "with confidence" is a very important qualifier that is drastically important to the meaning of that sentence. It's not a prerequisite for deploying at all, but without reviewing the entire codebase I cannot feel confident about its security.
- shampine 11y agoWhy do you feel you would need to review the entire codebase to deploy Gitlab? It is an apt-get installation now that they ported to Omnibus. The days of debugging gem errors on compile and migrating by hand are over.
- sarciszewski 11y ago> Why do you feel you would need to review the entire codebase to deploy Gitlab? I already answered this. Quoting my post above: > so I can deploy it with confidence Emphasis is important. Background: I do application security consulting. Do you expect me to trust the code that other developers write without verifying that it's not a pile of lacey Swiss first? Also, if I do find any bugs, I'll report them upstream (since they are open source) so my paranoia is probably going to be beneficial to other GitLab customers some day.
- jrochkind1 11y agoYou don't use any software you haven't reviewed the entire codebase of? How about the browser you're reading this with?
- sarciszewski 11y ago> You don't use any software you haven't reviewed the entire codebase of? This is a fallacy. You're putting words in my mouth, because I did not make that argument. I do not use any software WITH CONFIDENCE that I haven't reviewed the entire codebase of. I still use software I don't feel confident about using every day. > How about the browser you're reading this with? Use it, just not with confidence. I'm ready to wipe this computer's hard drive at the drop of a hat if it lets me down.
- sytse 11y agoWe welcome all the paranoia we can get. Please be informed that multiple organizations have done security audits for GitLab and we have paid external parties to perform them for us. That doesn't mean there are no bugs anymore.
- sarciszewski 11y agoMultiple organizations -> good! :) Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. Though I usually give them the benefit of the doubt and omit my feelings when I write my report. Maybe it was a time constraint or a scoping issue that prevented them from seeing it? I have no way of knowing. So, kudos for not having a single point of failure.
- jsmthrowaway 11y ago> Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked. And you've never missed one, right? Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app. Handle being questioned a bit better, if you can, and understand that seeing this immediately talks me out of using your services. (Even if you're an oracle who never makes a mistake, as you imply. I'll take my chances with someone a bit more professional.)
- sarciszewski 11y agoHave I overlooked bugs? Sure. Have I overlooked really obvious bugs? None so far that I've been informed of. I'm not careless when I get paid to audit a project. Of course, I know I'm not perfect either. One time, I was writing a PoC implementation of AES-CBC and forgot to authenticate the IV (which was included in the message). Luckily, someone called me out on it very early on. (As a result, I'm also more likely to catch this kind of mistake in someone else's work.) Making mistakes is part of the learning process. Making mistakes when assessing someone else's security is a very real danger. That's why I give GitLab kudos for using multiple organizations. The moral to the story I was telling, albeit poorly, is that "I think you're doing the right thing by having multiple teams look at your project". But that was my fault for not expressing this clearly enough. > Aside from this, your behavior in this thread is a very loud warning about working with you, particularly telling someone to learn to read below by linking to an app. Nobody who contacts my employer deals with me directly. The person who handles clients has people skills. I do the technical heavy lifting. So, please rest assured, that any "very loud warning" you're reading won't translate into the quality of services we provide, even if I am an asshole on my personal accounts. > Handle being questioned a bit better, if you can, and understand that seeing this immediately talks me out of using your services. (Even if you're an oracle who never makes a mistake, as you imply. I'll take my chances with someone a bit more professional.) I don't mind being questioned. I mind people demonstrating a blindness to the qualifiers I explicitly include in my statements.
- shampine 11y agoAdding emphasis to an empty word doesn't give it meaning. You answered my question but first you prefaced with asking me why I can't read your mind.
- sarciszewski 11y ago> Adding emphasis to an empty word doesn't give it meaning. It's not an empty word, it's a very important semantic detail about what I was actually saying. It was chosen specifically and purposefully to transmit that information. If you dismissed it as "an empty word", then the fault of this miscommunication is on your end. > You answered my question but first you prefaced with asking me why I can't read your mind. You chose to discard the information I already provided. You don't need to read my mind when every clue you need to piece together the intended meaning is written on the screen in front of you. (Or, if you're blind, maybe you experienced it as an audio stream?)
- deleted 11y ago[deleted]
- shampine 11y agoSimply put, you could have just answered the question. I wouldn't have asked it if you were clear about your meaning.
- sarciszewski 11y agoSorry, I don't know how to be clear to people whom treat the very important phrase "with confidence" as nonexistent in that sentence. Maybe this app will help? https://play.google.com/store/apps/details?id=com.interactive8.readmestories.learntoread&hl=en https://play.google.com/store/apps/details?id=com.interactiv...
- cooper12 11y agoThat's a funny double standard you have right there with how you don't feel the need to audit GitHub before using it.
- sarciszewski 11y ago> That's a funny double standard you have right there with how you don't feel the need to audit GitHub before using it. Where did I ever say I use Github with confidence? I've answered this several times below: I use software all the time that I do not feel confident about. My statement was about hopefully being able to use GitLab with confidence, which is a goal that is only attainable because I can deploy it on my own hardware. It's made easier by the fact that GitLab is open source. If GitHub melted tonight, I'd jump on GitLab tomorrow, but I wouldn't feel confident about the security of my infrastructure. That doesn't mean I feel confident about GitHub. AT ALL. I'm not attacking GitLab. I'm not inflating GitHub's security or importance. All I'm saying is that I'll hopefully have the opportunity to review it before a nuclear GitHub meltdown forces me to blindly deploy it and not feel confident about it. Can we all agree that that's an uncontroversial notion? Or is that too much to ask?
- cooper12 11y agoNo, that's reasonable. Thank you for clarifying, especially the distinction regarding GitLab being self-hostable and open-source. Apologies if my comment came off as accusatory, I really did find it funny—as in peculiar—because I have seen people have a bias towards the quality of open-source software even though the closed-source alternative is opaque.
- sarciszewski 11y ago> Apologies if my comment came off as accusatory, I really did find it funny This thread has been a land mine of accusatory reactions, so I apologize for painting yours in a similar brush. > I have seen people have a bias towards the quality of open-source software even though the closed-source alternative is opaque Reverse engineering isn't hard, it's just a speed-bump. I work on a lot of open source projects. At the risk of sounding self-promotional to on-lookers, I'd like to talk about one in particular: https://github.com/paragonie/random_compat https://github.com/paragonie/random_compat https://packagist.org/packages/paragonie/random_compat https://packagist.org/packages/paragonie/random_compat Random_compat has been downloaded almost 2 million times (according to Packagist), incorporated into WordPress, Laravel, Symfony, etc. It's by far the most collaborative project that Paragon Initiative Enterprises has produced for the open source community. Yet, until the most recent release, the documentation referred to a MCRYPT_CREATE_IV constant that does not exist. The correct constant is MCRYPT_DEV_URANDOM. Somehow, we all missed it. "Open source is automatically more secure" is a fallacy. I just happen to like open source better, personally. Aside: despite being downloaded ~1.9 million times, a grand total 30 people outside of Paragon have contributed to its development in some way so far. The "many eyes" are actually quite sparse, especially when it comes to security expertise. (I think it's reasonable to say those 30 represent much of the the upper 0.01% of security talent in the PHP community.)
- touristtam 11y agoor go for gogs and learn go along the way? ;p