12 ms·
WordPress 5.2: Mitigating Supply-Chain Attacks
- nindrax 7y agoFtid
- huxflux 7y agoPerhaps HN should give Wordpress a thumbs up for once! I start, nice.
- jaden 7y agoAgreed, Wordpress has come a long way,along with PHP for that matter. Both deserve a little more praise and less criticism for the warts of bygone days.
- ddebernardy 7y agoThere has been chatter about doing this for over 8 years in the WordPress bug tracker, and I vaguely recollect chatter about it even earlier, around when automated updates were first introduced. What's surprising is that this hasn't been done earlier, and speaking personally I do not think this deserves any praise - on the contrary. https://core.trac.wordpress.org/ticket/18577 https://core.trac.wordpress.org/ticket/18577 - Updates and downloads should be delivered securely (signed and delivered over SSL), opened 8 years ago, partially closed 6 years ago (because it began to use SSL). https://core.trac.wordpress.org/ticket/25052 https://core.trac.wordpress.org/ticket/25052 - Updates and downloads should be signed, opened 6 years ago, closed 6 days ago. https://core.trac.wordpress.org/ticket/39309 https://core.trac.wordpress.org/ticket/39309 - Secure WordPress Against Infrastructure Attacks, opened 2 years ago, closed 12 days ago.
- someexgamedev 7y agoI set up a WordPress site for a family member a couple years ago and threw wordfence on there just to see what the ecosystem is like. I get near daily alerts of attempted hacks mostly from Eastern Europe. Most common thing is trying to brute force the login page. Any improvements to WordPress security are welcome. It's got such a huge target painted on its back. Reminds me of windows in the 90s. As for what I learned, I would move the admin login page and disable common usernames like admin and anything derived from the site url. Probably stop 90% of attacks just with that.
- zigzaggy 7y agoThat’s good info, thanks. I just happen to be looking into WP security right now. Would you recommend wordfence in addition to the changes you mentioned?
- xenospn 7y agoI highly recommend wordfence. I have it set to immediately block anyone after a single failed login attempt.
- kijin 7y agoIt's fairly resource-intensive, though. I've seen whole servers brought to their knees because of plugins like WordFence -- an unintentional DoS, so to speak. Many of the defenses employed by WordFence would be orders of magnitude more efficient if implemented at the level of the http daemon or firewall. Unfortunately, WordPress plugins must cater to the lowest common denominator, shared hosting.
- xenospn 7y agoIf what you’re dealing with is thousands of attempted brute force attacks on a daily or weekly basis, a wordpress plugin might not be the solution.
- kijin 7y agoSure, but you don't know that until the attacks actually begin, and anyone can attack any site for any reason these days. Meanwhile, most people who run WordPress sites don't know how to do anything more complicated than installing a plugin. Being a developer who caters to that market has its own charms and challenges.
- HNthrow22 7y agoto offer a counter opinion I found wordfence highly obtrusive, annoying and full of dark patterns in an attempt to upsell you to premium. They present in their dashboard ALL attacks within their entire network as if those were attacks on your site in particular which is misleading. If the project permits the best practice is to convert the site into fully static HTML (WP2Static, SimplyStatic) and keep the backend site/database separate and local only.
- pepoluan 7y agoI misread that as WordPerfect 5.2 ...
- dplgk 7y agoI have old WordPress blogs sitting around. They got hacked of course. Because they are so old, it would be a huge pain to upgrade. I restored from backup and chmod 550 the whole WP installation. Much easier than upgrading and less time than migrating to static blog framework.
- Angostura 7y agoIf they are simplish blogs, I can't see that there should be any difficulty in updating WP and the theme, and you'll be doing the rest of the Internet a service.
- ggm 7y agoI think this is very good because it reduces the attack surface for people who track current code. It's important to remember a large set of un-updated nodes will remain. Not that anyone can do much, but equally not that the entire surface of bad Wordpress will go away. I would be interested how big the long tail is. one third? more? It is also worth thinking about the code signing problem firefox just had, and reflecting on the possibility of the hack in the head still taking place: either a denial-of-service or a bad code intrusion risk remains. Its far far less likely, and it can be mitigated, but this is the reality of distributed systems: You can only do the best you can, nothing is guaranteed. (even TMR units fail)
- kiesel 7y agoThe update mechanism itself is still insecure, as the wordpress instance must have the ability to exchange its own source code - something you'd at least call risky. Web applications should run with the least possible privileges, ie. only with permissions to write to dedicated locations on the filesystem (user uploads), and read permissions for the code. PHP has composer, a dependency management system. There's an option to build a wordpress project using composer. Even more, there's even a boilerplate project that you can use to bootstrap your new wordpress setup - see https://roots.io/bedrock/ https://roots.io/bedrock/
- ahje 7y agoProblem is that there's a ton of shared hosting providers that won't support such a setup, as it would require a lot of modifications to 1-click-installers for WordPress. General WordPress users have no idea about such things, and the demand for more elegant solutions is therefore quite small. That, and the fact that WordPress popularity stems from the fact that it's fairly easy to set-up without technical know-how, makes it unlikely that another path will be chosen in the close future.
- CiPHPerCoder 7y ago> Web applications should run with the least possible privileges, ie. only with permissions to write to dedicated locations on the filesystem (user uploads), and read permissions for the code. This isn't wrong but I'd argue it's a lower priority concern than you believe it is. A comprehensively secure automatic update system would have process isolation between the normal web interface and the updater (and the latter would run as a different, more privileged user). However, not everyone can do that. (Shared hosting, etc.) https://paragonie.com/blog/2016/10/guide-automatic-security-updates-for-php-developers https://paragonie.com/blog/2016/10/guide-automatic-security-... The goal of an automatic update mechanism should be to prevent the rampant exploitation of 1days, like what happened with Drupal not too long ago. If you had to choose between "owned within 7 hours of the advsisory" or "less theoretically secure in a constrained environment but still securely self-updating" in the CMS/blog threat model, the latter wins. There's no easy way to rearchitect WordPress to support the principle of least privilege and process isolation for their auto-updater in a way that ensures everyone still uses it. So for the time being, that's worthy of being called out, but isn't a big enough deal to label the whole shebang insecure. Because "insecure in which threat model?"
- oliwarner 7y agoCriminals: We can break 33% of the internet with one wrench! Because that's what this still comes back to. If you can bribe or intimidate one developer with valid credentials, you can sign as many hashes as you like, if nobody else reviews and catches that commit, the users are toast. And even if Wordpress has a strict review policy, what about the plugins? There are some furiously popular examples out there made by very small teams, well outside Automattic's control. All in all, there are thousands of people out there that one or two swings of a wrench mean that a massive network of servers become compromised. And in many cases you might not even need that. Hack the personal computer of one of these people, and you're 99% done. Sleep well.
- eitland 7y ago> In the future, we will be working to implement a system that allows vendors to sign their own releases and publish these signatures (and related metadata) to an append-only cryptographic ledger. Without dismissing all crypto currencies this seems more immediately practically useful:-)
- Ninn 7y agoSoo, almost exactly like the Apple Store works? But just without a high performance database.
- CiPHPerCoder 7y agoIf you're curious: https://paragonie.com/blog/2016/10/guide-automatic-security-updates-for-php-developers#decentralized-authentication https://paragonie.com/blog/2016/10/guide-automatic-security-... https://paragonie.com/blog/2017/07/chronicle-will-make-you-question-need-for-blockchain-technology https://paragonie.com/blog/2017/07/chronicle-will-make-you-q... I've written a lot about the design and utility of append-only cryptographic ledgers for this use case. Mozilla has their own implementation based on Certificate Transparency: https://wiki.mozilla.org/Security/Binary_Transparency https://wiki.mozilla.org/Security/Binary_Transparency Filippo Valsorda is working on bringing something similar to the Go ecosystem, based on a Trillian personality. There's a lot of work going on, there's just not a marketing team behind these efforts, so you only ever hear about blockchains and ICOs.