8 ms·
I “found” the database of a college app (2018)
- hyperthreading 7y agoIs there any way to hide keys from the extractions? I tried it before and ended up to find that users can do that if they really want to.
- petjuh 7y agoNo, but I think the idea is to create a web API that connects to the database instead of having the phone connect directly to it.
- bootloop 7y agoNo, you can only obfuscate it but the correct way to do this is to limit the access scope of the access key.
- yoginth 7y agoI think we can't hide keys up to my knowledge! But make sure you just switched firebase to production mode. In my case, the firebase was in development mode and the data is available public! https://yoginth.com/college-hack#mitigations https://yoginth.com/college-hack#mitigations
- evolveyourmind 7y agoIt’s not about keys or modes, it’s about the rules they didn’t set up. Everyone uses firebase like that. Those “keys” are required to allow you to connect to the correct firebase app, nothing more. You don’t get any direct special permission to do things on the database or storage. Here some more info about the rules: https://firebase.google.com/docs/database/security https://firebase.google.com/docs/database/security
- whymauri 7y agoI'm not a mobile dev, but aren't there utilities like KeyStore for this? https://developer.android.com/training/articles/keystore.html https://developer.android.com/training/articles/keystore.htm...
- bootloop 7y agoWell, the trick is that using a KeyStore ensures that the key doesn't leak into the application (but is only used for cryptographic operations in a trusted environment). However, you would need the plain key to authenticate against the database so using this wouldn't work.
- whymauri 7y agoGotcha, I see the problem now.
- diericx 7y agoFirebase keys give you access to the database, which can be public. You just have to setup rules for the database, usually so users have to be authenticated to view anything and can only read their own private info. edit: just realized you may have just been asking about hiding keys in general. Sorry if this wasn't what you were asking about!
- hyperthreading 7y ago> Don’t put your API keys, Tokens and Secrets visible easily I was just confused at this part because permission & rules are the solution as far as I know. Thanks for the reply though :) I'm prettry sure now that exposing keys are no problem.
- noja 7y agoRead-only access through intermediate proxy that you control (but not to all data like here) + login required for more access (via intermediate proxy or direct).
- q3k 7y agoNo, you can just obfuscate it and make it painful to extract to potential reverse engineers.
- ggggtez 7y agoVisible key isn't the bug. The bug is that the app should not have read access to other students.
- anarchodev 7y agoYep. Although this exact thing has happened to so many apps I’m beginning to doubt the wisdom of this “allow completely open dev settings at first and then YOU get to remember to fix it” model that fire base uses. Maybe they could require an IP whitelist if the permissions aren’t set yet or something.
- rrix2 7y agoThis is the cause of many mongodb and redis woes as well.
- gchamonlive 7y agopermissions are a pain... i am considering centralizing permission handling in a separate service environment so that every service I have shares the same permission logic. It is a shame since we could save some latency time by having permissions implemented in the same language and app that it is being requested. But to avoid stuff like that in the article I believe the cons are worth it edit: the user had direct access to the database. No amount of code would mitigate that. Moral of the story is NEVER leave your database open to public, always hide it behind a service wall
- NKCSS 7y agoSecurity and usability are always at the opposite end of the spectrum. Balance it wisely.
- AmericanChopper 7y agoThis is such a dangerous false dichotomy. Plenty of security systems benefit user experience.
- servercobra 7y agoAs far as I know, none of these keys (except the email/password) are considered a secret. The real problem here is that they aren't using Firebase/Firestore rules to correctly limit database access.
- noja 7y agoITT everybody doing the same!
- mappu 7y agoIs Gitote a fork of Gogs/Gitea?
- yoginth 7y agoIt's a fork of Gogs!
- deleted 7y ago[deleted]
- kazinator 7y agoA school that tracks attendance cannot be called a college or university. Kindergarten, I can swallow.
- stedaniels 7y agoI'm not sure if you are in the industry, but attendance tracking is high up on most institutions lists of metrics to track. Aside from helping out the usual back office data, it's often a key indicator for students who are in trouble. The institution can then reach out and assist these students.
- rocqua 7y agoI think OPs point was about using attendance as part of assessment.
- tastroder 7y agoThey might just not be from the US. Here in Germany, tracking or forcing student attendance is subject of large discussions and generally often frowned upon (or forbidden by regulation) in the University setting these days.
- stedaniels 7y agoThis is mind boggling. Failing someone for missing one or two classes is ludicrous, but giving someone a certificate who didn't engage with the course is equally so. University education isn't about the destination/exam it's about the journey.
- tastroder 7y agoNot sure why you'd think that not tracking attendance means that people do not attend. Pure attendance does not guarantee good performance and in filled lecture halls there's often not much to "engage" with anyhow. We see this as academic freedom, if you miss out on in-person seminars you won't pass, if you do not go to some lecture because you have to work and teach yourself afterwards, who cares.
- z3t4 7y agoThis seem to be the default on most G services.
- AlphaWeaver 7y agoWhat makes this even more sloppy for the school is that I know for a fact that Firebase will send your admin account an email when it detects that you have weak security settings on your database. It also sends said email repeatedly, once per day. I know because I intentionally have a developer db that is read access for the whole world and I get that email every afternoon. The admin of this app either is not competent enough to know what that email means, or is willfully ignoring it.
- mattlondon 7y agoOr registered on a "throw-away" gmail account created for this app that no one is reading.
- bartread 7y ago> The admin of this app either is not competent enough to know what that email means, or is willfully ignoring it. Or it's being filtered into their junk folder. I'm not making excuses for them, btw (there's just so much else wrong here): just pointing out that this happens quite often with even legitimate automated messages.
- MRD85 7y agoThe media would have a field day and say that he hacked his school database. It's crazy how so many institutions are doing the digital equivalent of leaving an unlocked car in a bad neighbourhood and no one holds them accountable. Most people understand the concept of an unlocked car, not many understand that he didn't do anything special to hack his school db. He just strolled right in.
- julvo 7y agoExactly, it's like leaving your customers' cars unlocked in a bad neighborhood
- scoot 7y agoLike keeping your unlocked filing cabinet on the front porch...
- fyfy18 7y agoI did this when I was at high school with a friend. Basically the place had a shared Windows file system, and the only thing that prevented everyone from viewing it was that it was hidden in the UI. On the drive was lots of data, including some applications in PDF format - completely unprotected - full of personal information of minors. At the time we had recently covered data protection in IT class, so we wrote up a document explaining what we did, and why it was bad, and gave copies to a few people in prominent positions (principle, head of IT, IT teacher) as well as posting it (with instructions redacted) on an internal message board. Well of course they didn't take it very well. They threatened to expel us and call the cops, and suspended us for a week until they decided what to do. In the end a well written warning from my friend's parent made them drop the issue and let us back in. I doubt they did anything to change the "security".
- hjk05 7y ago> he didn't do anything special to hack... Someone who snatched a purse out the hand of someone else isn’t “doing anything special” either. The illegality doesn’t hinge on the difficulty of the action. Why is that so hard to grasp for technical crowds? If you find a car with the keys in the ignition and the door unlocked, you won’t get away with driving it a block down the road by telling the judge: “Oh, but it was obviously insecure, and I was just testing to see if I could steal it”.
- sammnaser 7y agoGood spot, but be careful in the future in your approach. Some places will nail you for having not stopped at the point where you unpacked the apk resources and noticed the API keys. Downloading the credentials might not have been the smartest move.
- kadira 7y agoLOL, this is nothing new.
- aitchnyu 7y agoI had to code-review a Django app using Firebase as a DB and swore never again. He did features and promised to do validation and security later by going to their editor and writing Javascript files. Django lets him write valid forms and correct SQL queries in almost same lines of code. Pagination was a pain in current version and present only in a version forever in beta. All the hard work coaching him on exceptions went out of the window. An Android dev finally enlightened me where Firebase shines: offline sync of mobile to a server by eliminating lots of explicit CRUD calls and error handling.
- zeristor 7y agoIsn’t this the opening to film Wargames? Has Joshua asked you to play a game of global thermonuclear war yet?
- empath75 7y agoI’m not familiar with Firebase, but is it unusual for end users to have direct access to a database at all? Why isn’t there a web front end there?
- wildrhythms 7y agoFirebase has a "rules" feature where you set up security/authorization rules on your database: https://firebase.google.com/docs/database/security#section-authorization https://firebase.google.com/docs/database/security#section-a... There's a "development" mode you can enable on your database that simply ignores all of the rules. The college app either 1) has no/unsafe rules set up, or 2) left their Firebase database in development mode.
- bayareanative 7y agoAn Australian autistic developer found a top university's custom authentication database exposed to the internet in less than 10 minutes. Please, no more DIY crypto or running unaudited services willy-nilly. :prayer-emoji-here:
- throwaway527694 7y agoDid someone verify any of this? If I recall correctly this `yoginth` is a known fraudster. See: https://twitter.com/sindresorhus/status/1015873644377935874 https://twitter.com/sindresorhus/status/1015873644377935874 or https://twitter.com/natfriedman/status/1059865722904440833 https://twitter.com/natfriedman/status/1059865722904440833
- yoginth 7y agoHey, that is too old and I have done it without knowledge, it's my mistake and I apologized for all of them personally and publicly! Here this app belongs to my college, it's my attendance and work is mine!
- uponcoffee 7y agoHow does one plagiarize and attempt to profit off somebody else's work without knowing it? It's ingenious to say you've apologized while at the same time saying you didn't knowingly do anything.
- surelyyoujest 7y agoYou've built an entire online presence by copying everything from other people's work - from your blog theme to your content "without knowing"? Adorable. Also, by briefly reading the docs on the "platform" you are trying to peddle, I'm getting fairly certain you also copied that as well, as it is too well written in comparison to the drivel on your blog.
- jsty 7y agoIn all fairness on that last point, if you're referring to his "Gitote" project, the author has stated here [0] that it was a fork of Gogs, and seems to have retained the proper copyright notices in the source files: "// Copyright 2015 - Present, The Gogs Authors. All rights reserved. // Copyright 2018 - Present, Gitote. All rights reserved." [1] I agree it should probably have been given more prominent mention, but given the number of commits doesn't seem (at quick glance) to be a hasty "fork and rename". [0] https://news.ycombinator.com/item?id=20137624 https://news.ycombinator.com/item?id=20137624 [1] https://gitlab.com/gitote/gitote/blob/master/gitote.go https://gitlab.com/gitote/gitote/blob/master/gitote.go
- daevoncrafter 7y agoIs there any way to encrypt strings.xml file?