5 ms·
This is the lesson to learn from Elixir/Phoenix and every web framewrok that does not come with a strong security concept: if you do not build solid authenticat
by softwarelimits 8y ago
This is the lesson to learn from Elixir/Phoenix and every web framewrok that does not come with a strong security concept: if you do not build solid authentication and authorization into the framework from the ground up, there will pop up bazillions of half-baked libraries and even more blog posts about how to do auth "the right way" and still there will never be the right way as long as the framework does not implement this.
Many eyes on security relevant code is one of the most important reasons for using open source frameworks for web development - so it is very unfortunate if exactly this part is missing, it will always look incomplete.
Of course this leaves room for professional services, I understand that, but I believe the damage done is greater than the opportunities generated. The current situation for "Phoenix auth libraries" is horrible - as a developer you will
* waste a lot of time researching and testing all the available solutions
* or just take one "random solution from the internet" that "looks good enough"
* or you will just implement another solution yourself.
Instead you want to build on the solution that is provided and maintained by the core framework community.
This is such a sad story. Elixir / Phoenix looks so nice, but without a strong security foundation it looks incomplete. Authorization and Authentication is not even mentioned in the docs - that is absurd!
I simply can not understand why the project leaders are ignoring this important area.
- imtringued 8y agoAt some point it isn't even possible to avoid having special libraries to support authentication. No one is going to roll their own library for SAML, Oauth, etc.
- impostir 8y agoI am just learning coding for the web. Security is something that is clearly important, but I am unsure on a lot of specifics. Do you have any suggestions for a beginner?
- sansnomme 8y agoLearn how basic user registration to login workflow works. I.e. user sign-up -> password hashing -> confirmation email etc. There are also "alternative" methods such as medium-style "email a login link" style logins and also stuff like OAuth. Stick with large frameworks and libraries; Rails, Omniauth and Devise, Django comes with Auth built-in. Avoid Auth frameworks which doesn't build upon its built-in systems. Learn the difference between authorization and authentication. DO NOT ATTEMPT TO ROLL YOUR OWN AUTH FOR PRODUCTION. A lot of concepts regarding Auth are simple in theory but if you have a poor grasp of the implementation language or the authentication protocol, you are going to introduce vulnerabilities. Stick to boring battle-tested stuff. Yes that means you should avoid the latest-web-framework-of-the-week-that-doesn't-include-auth when it comes to anything you want to push into production. Keep everything behind TLS if possible (Let's Encrypt et al. are free) and if you don't understand something, don't use it. If JWTs doesn't make sense to you, avoid it and stick with traditional sessions. Your SPA works perfectly fine using traditional server-side sessions and encrypted cookies without the latest hip protocol implemented by a 3rd party API gateway. Don't trust security advice from random people over the internet without doing your own research. Here is some good reading material: https://latacora.micro.blog/2018/06/12/a-childs-garden.html https://latacora.micro.blog/2018/06/12/a-childs-garden.html https://latacora.micro.blog/2018/04/03/cryptographic-right-answers.html https://latacora.micro.blog/2018/04/03/cryptographic-right-a...
- sansnomme 7y ago*server-side sessions with CSRF
- lobo_tuerto 8y agoI touch on some basic (but well done AFAIK) auth stuff over here: https://lobotuerto.com/blog/building-a-json-api-in-elixir-with-phoenix/#simple-authentication https://lobotuerto.com/blog/building-a-json-api-in-elixir-wi... I think the main reason it's not in the docs it's because in the end it's just an implementation detail. Have a look at how simple it is to protect some routes that needs the user to be logged in.