4 ms·
This is, maybe counterintuitively, not true. If anything, Coinbase is more secure than before by publishing this. For a great and well-reasoned argument see th
by mxstbr 9y ago
This is, maybe counterintuitively, not true. If anything, Coinbase is more secure than before by publishing this.
For a great and well-reasoned argument see the Gov.UK guidelines, which state that all of their new code has to be open source. (yes, that's the UK government, not some startup) They even specifically mention security-enforcing code![0]
> Code that contributes to your service’s security does not need to be kept closed. Many security-enforcing functions, such as cryptographic algorithms, are provably better when openly examined and understood while the keys are kept private.
They also have another guide and a blog post specifically about security considerations with open source code.[1][2]
> Doesn’t it give attackers an advantage?
> Although there’s a common concern that coding in the open could give an advantage to an attacker, we believe that only a negligible advantage exists. [...] In fact there is no evidence to suggest that being open source makes software more susceptible to exploitation.
I would highly recommend reading through those if you really think Coinbase is now under a higher risk of attack due to this article. They aren't.
[0]: https://www.gov.uk/service-manual/technology/making-source-code-open-and-reusable#making-code-with-a-security-enforcing-function-open https://www.gov.uk/service-manual/technology/making-source-c...
[1]: https://www.gov.uk/government/publications/open-source-guidance/security-considerations-when-coding-in-the-open https://www.gov.uk/government/publications/open-source-guida...
[2]: https://mojdigital.blog.gov.uk/2017/02/21/why-we-code-in-the-open/ https://mojdigital.blog.gov.uk/2017/02/21/why-we-code-in-the...
- 1ba9115454 9y agoThere's no proof there that they are now at less risk. I've looked at the code and I can see already some potential supply channel attacks as they are not hash protecting their incoming libraries.
- cormacrelf 9y agoIt seems to be extrapolated from open crypto code, which is a unique example. Nobody goes around volunteering security reviews of CRUD apps like they do for interesting crypto. If you're open sourcing stuff that other people use, it makes sense, because people fix security issues from using software, fixing bugs and witnessing failures, and needing the fixes for themselves. Not from going 'wow, that's 500 repositories, most of which I don't care about at all'. You're not going to go fix the issues you just saw, are you? In this case, Coinbase open-sourced some useful code (with an install-this-one-liner), and details of a systematic security method that other people can also use themselves, critique and improve on. The difficulty of breaking their setup hasn't changed, simply by knowing that the keys/MFA combo you really want is a different one. You'd still need to steal it. Perfect example of helping security by transparency.
- ncallaway 9y agoSure, but that can easily be turned back around on you: There's no proof there that they are now at more risk. > I've looked at the code and I can see already some potential supply channel attacks as they are not hash protecting their incoming libraries. And if you, or anyone else who sees that sends them a notification about a potential vulnerability and they investigate it they're probably better off than they were before.