5 ms·
After reading the API docs, it appears that the FCC operates a mini-imgur/pastebin/file hosting service to help attach files to FCC filings: https://www.fcc.go
by phsource 9y ago
After reading the API docs, it appears that the FCC operates a mini-imgur/pastebin/file hosting service to help attach files to FCC filings:
https://www.fcc.gov/ecfs/public-api-docs.html#Full-Filing-Step-1---Upload-Files https://www.fcc.gov/ecfs/public-api-docs.html#Full-Filing-St...
Unfortunately, these "temporary" file uploads end up accessible from the main FCC domain (i.e. fcc.gov), unlike e.g., Google (e.g., "googleusercontent.com" vs. "google.com"). In Google's case, the separate domain helps distinguish the content as unofficial.
It's understandable why it was originally engineered this way, since it's probably easier to create a subdomain under fcc.gov rather than to get an unrelated domain, but that's why we ended up here!
- throwaway2016a 9y ago"Easier" is a relative. And in this case relatively small. The server and DNS configuration you need for a subdomain is identical to what you need for separate domain. Possibly slightly more to manage if you are using the "naked" domain because of the DNS issue with not supporting CNAME records on the naked domain. If you already have a wildcard SSL certificate for the subdomain a separate domain might be more work because you need a new cert and you don't if you stick with a subdomain. The most work is actually buying the domain. Then again, this is government we are talking about so buying a $10 domain is probaly three weeks worth of paperwork.
- mattmanser 9y agoMore likely that the developer didn't even think about it, I know I probably wouldn't.
- Filligree 9y agoYou should! There are security implications galore, mostly due to the same-origin policy. Books can and have been written about web security; if you're writing webapps, you need to read one.
- mattmanser 9y agoI'm not saying you shouldn't think about it, it's just a non-obvious vulnerability.
- Filligree 9y agoMost of them are. Thus the book.
- mattmanser 9y agoMy feeling is that it's like computer security, you can bleat all you like about how the millions of developers have to magically know this stuff, or you can build it in by default. One method works, one doesn't. But keep on telling people to read a book, for all the good it will do.
- Filligree 9y agoIt's not like I'm in any position to do what you're suggesting. It's a bit late to revamp the entire web "security model" by this point.
- doingmything 9y agoAnd how many layers of red tape do you think the dev would have to go through to get a new domain?
- throwaway2016a 9y agoOn my team as a private company it looks like: Dev: "Can I have a domain?" Me: "Sure" 10 minutes later done In government I imagine you need a procurement order which needs to be approved. And my anecdotal experience has been that the dev teams don't always take high priority in those queues. I'm sure it's not as hard as I made it out to be but it is certainly not as straight forward as many of us are used to.
- namdnay 9y agoIt's not really linked to private vs public. It's more of an organisation size question. I can guarantee that if you were working in a megacorp it would be the same issue
- 52-6F-62 9y agoI work in a megacorp. Can confirm. Have to file tickets, and they have to seek approvals for either delegation of server allotments and subdomains or new dns pointers or worse. I regularly need to host internal applications accessible by other staff and often just do so from my machine during the daytime and send them updated IP addresses/ports where they can access them... boss didn't even think it was possible... Yeah. I imagine the government processes are pretty convoluted.
- xenophonf 9y agoThen again, this is government we are talking about so buying a $10 domain is probaly three weeks worth of paperwork. It's not that bad. It is slightly annoying that the procurement rules don't let sysadmins buy multi-year domain registrations---not even for .gov domains. Ultimately, there's nothing stopping a federal employee or contractor from buying another domain except ignorance of good infosec practices. Even a .gov domain isn't all that expensive---$400/year is a drop in the bucket of federal spending.
- jimktrains2 9y agoWait, .gov domains cost money? I guess I just thought the us government assigned them as needed to agencies. Never thought about cross agency bills.
- xenophonf 9y ago41 CFR part 102-173, the law that authorizes GSA to run the dot-gov registry, allows them to recover their operational costs from registrants: https://www.gpo.gov/fdsys/pkg/CFR-2010-title41-vol3/xml/CFR-2010-title41-vol3-part102-id2024.xml https://www.gpo.gov/fdsys/pkg/CFR-2010-title41-vol3/xml/CFR-...
- jimktrains2 9y agoIt completely makes sense, I just never thought about it.
- 27182818284 9y agoA lot of public universities had a homegrown dropbox lurking somewhere in their infrastructure. Thankfully they were already abused to the point that schools have been shutting them down over the last 5-10 years. (Usually abuse not in the form of malware, but in the form of file sharing movies, etc)