5 ms·
> Having restrictions on filetypes is a bug, not a feature. It should be - but for many school IT security types it really is a feature to limit file types
by shinjitsu 7y ago
> Having restrictions on filetypes is a bug, not a feature.
It should be - but for many school IT security types it really is a feature to limit file types
- TeMPOraL 7y agoSecurity: it seems to me that in the wild, 40% of it is security theater, another 40% exists primarily to ruin your mood and control you the user, and remaining 20% is actually around the right trade-off between utility and safety.
- scarface74 7y agoI agree that it is mostly theatre. I understand not allowing an exe, but if you have to download the file and rename it, how much of that would be unintentional?
- thisisbrians 7y agoAgreed, but trusting the extension at the end of the filename for this purpose screams, "amateur hour."
- usrusr 7y agoExtensions were important to filter when Windows explorer was still lacking rules to forbid file execution based on provenance, but was already defaulting to a) hide the file extension and b) display whatever pixels were embedded in an executable as the file icon. The combination of a) and b) was making even moderately security aware users utterly defenseless.
- MarcScott 7y agoI fought this during my entire teaching career. Blocking file types by extension is pointless. as you can just change the file type. If you're worried about kids being able to run arbitrary python scripts on your network, then the security problem is not the kids, it's your shitty network. People are given cash as bug bounties for finding security flaws in systems, but in schools they are punished!
- nighthawk648 7y agoCould not agree more!!! What about security patterns for web browsing? I feel the logic is somewhat similar but injections to websites / applications may be easier and hard to prevent against, so filtering pornography may be useful. I’m a dev not a security expert so sorry in the lack of understanding. I am actually trying to learn more about security / hacking
- noobermin 7y ago>If you're worried about kids being able to run arbitrary python scripts on your network, then the security problem is not the kids, it's your shitty network. How is this even possible? Unless your CMS runs on python somewhere and does eval() a lot. Then yes, that is a huge problem. Moreover, why would that stop anything just not called .\+\.py? If your CMS does `python ${fileIjustdownloadedfromuser}` in a shell then we are in serious trouble.
- cnst 7y agoI think it's also a problem when people are rewarded for finding these kinds of bugs that are not actual bugs. Some bad person vandalised an obscure public Oracle repository on GitHub that's not even for any public product they're known for (OpenGrok). Instead of being banned, the owners restricted public edits. WTF? It's small things like this that end up being having the anti-pattern become the norm.
- vxNsr 7y agoO365 blocks ps1 files by default. ps1 files aren't executable by default on any windows machine. why is the vendor that makes the OS (MS) making these types of decisions?
- madelyn 7y agoThis reminds me how for awhile I was emailing myself .tar and .exe files through Gmail or school email systems by renaming them to .jpeg files. Recent-ish (past year) Gmail patched this (for .tar at least), so I started using base64 encoded text files. Now though I just pay for my own email service away from Google.