11 ms·
How We Engineered CMS Airship to Be Simply Secure
- ogig 10y agoI've been using S3 static sites more and more and I think that exposing any kind of CMS control panel to the internet is a bad idea. Take a look at the list of security concerns Airship tries to manage. Most can be avoided by separating the content creation aspect and the publishing platform. Content creators represent the smallest audience group your site has, why then have a full application exposed to the internet running only for them to easily change content? Content creators should have an offline app, make changes, press publish and have those changes uploaded to a static server. The whole CMS control panel paradigm seems kinda flawed to me.
- devwastaken 10y agoHardly is it that static content is the way to go when you're working with any sort of dynamic data. If you're just making blog posts, Airship most likely isn't for you. An offline app would cause a number of its own problems in that regard, because now you're actually having to design a backend that interface with your webserver and puts the content to it. What happens when you have multiple editors? You're now pulling information from a central resource, which is going to be over the internet, whether its on a different server or not. Not to mention, by having it 'offline', you can't have mobile apps to edit content on your site. Static definetely has advantages, but when scaled and working with data its not that simple.
- CiPHPerCoder 10y agoOne of the projects on our to do list is actually creating a static publishing module that can be used for either: - Offline editing for online publishing - Static mirrors to resist censorship in the face of DDoS Updates would be sent from an Airship to a static hub, using challenge-response authentication, with Ed25519 signatures. Aside from the API that receives data and triggers an update (which is intended to be set up on a different vhost), the attack surface will be minimal. The only reason this isn't already a thing is that I've had other projects that were higher priority, including one I'll be releasing in a month or so (but probably not submitting to HN; it's an entirely commercial project).
- megous 10y agoWhat always boggled my mind was escaping data on the input side. Yet once it was quite popular. PHP even had option to do it automatically. What a weird idea. You escape data to prevent mistaking it for code whenever you use them in some context. You don't know the context when receiving the input.
- jarofgreen 10y agoThe only people I know off doing that now are WordPress. Modern PHP really has come a long way. (And in it's defence, a lot of good PHP at the time didn't use this auto-escaping feature. It was the PHP's designers flawed [as you point out] attempt to try and stop bad PHP developers shooting themselves in the foot.) In fact, while I found the article interesting I could have done with a bit less of the barbs about other frameworks. If the only way you have of building up your own tech thing is by tearing down other people's ...
- orf 10y agoAfter a quick peruse of their github repository I have to say there is some dodgy[1] stuff going on. As ever with PHP sites validation seems to be a mess. For example we've got a `escapeSupplierName` function[2] used in some places[3], but a different regex used when creating a suppier[4]. Variants of that regex also appear all over the code, why not put it in a single place? Properly escaping SQL injection is great (and something PHP apps seem to have a continual problem with), but why did you decide to roll your own framework for doing this? Are all of the well maintained, tested and great ones already available not suitable for some reason? It's just your app turns into a hard to check, inefficient[5] sludge, full of lots of code for handling framework related things like an ORM, caching[6] (that code is practically duplicated in a lot of places[7][8][9][10]), escaping[11], mime whitelisting[12] etc and not much about a CMS. This is where security bugs appear. 1. https://github.com/paragonie/airship/blob/eb4293aee5be59e329015520de7e0e44c3593ee6/tools/hangar/src/Command.php#L233-L237 https://github.com/paragonie/airship/blob/eb4293aee5be59e329... 2. https://github.com/paragonie/airship/blob/c4c9384d4d7860738d4965ed0be9f8a27c18e1ca/src/Engine/Bolt/Supplier.php#L77 https://github.com/paragonie/airship/blob/c4c9384d4d7860738d... 3. https://github.com/paragonie/airship/blob/c4c9384d4d7860738d4965ed0be9f8a27c18e1ca/src/Engine/Bolt/Supplier.php#L97 https://github.com/paragonie/airship/blob/c4c9384d4d7860738d... 4. https://github.com/paragonie/airship/blob/95af23ca782e8ecb1083d31f8614a7ca532e3207/src/Engine/Keyggdrasil/TreeUpdate.php#L354 https://github.com/paragonie/airship/blob/95af23ca782e8ecb10... 5. https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3bfff510854a716f4b5579b/src/Cabin/Bridge/Model/Files.php#L1055-L1062 https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3... 6. https://github.com/paragonie/airship/blob/master/src/view_functions.php#L646-L681 https://github.com/paragonie/airship/blob/master/src/view_fu... 7. https://github.com/paragonie/airship/blob/master/src/view_functions.php#L718-L736 https://github.com/paragonie/airship/blob/master/src/view_fu... 8. https://github.com/paragonie/airship/blob/master/src/view_functions.php#L491-L510 https://github.com/paragonie/airship/blob/master/src/view_fu... 9. https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3bfff510854a716f4b5579b/src/motifs.php#L18 https://github.com/paragonie/airship/blob/63cf0661ba21cbb3f3... 10. https://github.com/paragonie/airship/blob/2a8a87934921ecda85cf6ec3cecc43800b88a200/src/Cabin/Bridge/Controller/Account.php#L222 https://github.com/paragonie/airship/blob/2a8a87934921ecda85... 11. https://github.com/paragonie/airship/blob/eb4638eb31510028f40d6b51d13f0005fc5f2d60/src/Engine/Security/Util.php#L135 https://github.com/paragonie/airship/blob/eb4638eb31510028f4... 12. https://github.com/paragonie/airship/blob/eb4638eb31510028f40d6b51d13f0005fc5f2d60/src/Engine/Security/Util.php#L81 https://github.com/paragonie/airship/blob/eb4638eb31510028f4...
- theamk 10y ago> Since Airship self-updates, it needs to be able to write to itself. > chown -R myusername:www-data airship > chmod -R g+w airship Have you ever wondered why some people say that PHP is insecure? That's one of the major reasons. This app claims to care about security, but at the same time it self-updates and has no external code integrity control. This means that if the webapp has a vulnerability which was exploited, it will be very hard to detect it -- was this file changed by auto-updater or by malware? you don't know. And even if the new version of webapp was released which fixes the bug, you can not be sure that infection is gone -- because the update process may also be compromised. And you cannot easily remove code dir and re-download -- the settings are mixed-in with the code. Compare it with any other stack -- Ruby on Rails, Django, JAR files, whatever. Code cannot modify itself. The only writable thing is the database. Additionally, the repository is often under git control. If there is a vulnerability, update software and restart the server (if in doubt, backup the database and nuke/rebuild the server instead). Even if you made a configuration error and left code dir writable, "git status" is enough to tell you any changed/added files. And this is why you, as an admin, should avoid PHP if you care about security. Sure, you can use sane techniques even with PHP code -- I am sure that's what Facebook and Wikipedia do -- but most random PHP projects will require writable code dir. When choosing a web app, choose non-PHP one first.
- dchest 10y agoAirship has most paranoid auto-update system I've ever seen. You can read about it here: https://paragonie.com/blog/2016/05/keyggdrasil-continuum-cryptography-powering-cms-airship https://paragonie.com/blog/2016/05/keyggdrasil-continuum-cry... It also convers the "external code integrity control": Keyggdrasil makes sure everyone sees the same public keys, prevents anyone from rewriting history, and makes targeted attacks noisy. Autoupdating is not a feature specific to PHP. You can do manual updates as you described with it too, so I'm not sure why you even contrast it to other languages or CMS. It's pretty much established that properly implemented autoupdates increase security, not reduce it. I agree that writeable and executable directory is a huge risk, though.
- CiPHPerCoder 10y agoWhat 'dchest said, but also: https://paragonie.com/blog/2016/10/guide-automatic-security-updates-for-php-developers#privilege-separation https://paragonie.com/blog/2016/10/guide-automatic-security-... Security at the expense of usability, comes at the expense of security. CMS Airship went with the "self-writing code" option because we believe the potential damage of a 1day vulnerability to be much a higher concern than theoretical "this isn't really following best practices grumble grumble". By all means, don't chmod/chown anything, and run continuum.sh as a more privileged user if that's what you want. Just don't disable automatic updates.
- Aardwolf 10y agoNames of tech products in hacker news titles can sometimes give a different image upon first read. This one made me think of engineers tinkering with mechanics on a giant flying airship :)
- xorraxrax 10y agoMy biggest problem with Paragon IE is the fact that its owner, Scott Arciszewski, continues trying to make it seem as though his company consists of anyone else other than just himself. From the kitschy redundant name (is it an Initiative or an Enterprise?) to the awful typography, web design and logos[1], to the fact that all of his blog posts and commits are anonymized as "P.I.E. staff", "paragonie-security"... There is clearly no-one else working for him. I'm not saying that crypto and security work should only be entrusted to large corporations, but this makes him come across as dishonest right off the bat. Scott, if you truly stand behind your software then you need to shed the corporate charade and promote it as yourself. And please get someone else to do your graphic design work in future. [1]: https://airship.paragonie.com/ https://airship.paragonie.com/
- CiPHPerCoder 10y agoYou are mistaken. https://www.corporationwiki.com/p/2ixe71/paragon-initiative-enterprises-llc https://www.corporationwiki.com/p/2ixe71/paragon-initiative-... That's all I will say about the matter.
- dang 10y agoThis crosses into personal attack. We've banned accounts that do this, so have banned this one.