5 ms·
Well, there is a known MITM vuln in Deno by design and the team refuses to fix it soooooo REF: https://github.com/denoland/deno/issues/1063 https://github.com/
by ecares 6y ago
Well, there is a known MITM vuln in Deno by design and the team refuses to fix it soooooo
REF: https://github.com/denoland/deno/issues/1063 https://github.com/denoland/deno/issues/1063
- crabmusket 6y agoLockfiles should be used for production code, as per https://deno.land/manual/linking_to_external_code/integrity_checking https://deno.land/manual/linking_to_external_code/integrity_...
- ecares 6y agoThat is not enough at all and there are other attacks! I can't belive in 2020 some people still need to be explained why not enforcing https is a terrible thing! For instance, will a lockfile prevent someone from eavesdropping on the download of a modules through http? If so, please kindly tell me how!
- 1_player 6y agohttps prevents MITM but doesn't prevent the modules being backdoored or otherwise altered at the source. I would prefer https-only, sure, but it doesn't buy you very much security.
- ecares 6y agoWell, diasabling http by default is basically "Internet 101" here. I don't want to write an full lecture on how many attacks are possible when people don't use https. It has been commmon knowledge for way more than a decade
- realharo 6y agoCan checksums/hashes be specified directly in the source file? EDIT: I mean hashes of dependencies. That is important for single-file scripts, if this is meant to be useful as a bash replacement for scripting. Having to download two separate files for a script and execute it with special arguments already adds too much friction to that scenario.
- ecares 6y ago>Can checksums/hashes be specified directly in the source file? That would defeat their point actually :D malicious attacker could inject any script by hacking on the network and replace modules that are downloaded through http
- realharo 6y agoHow? Say I have `script.ts`. That file exists locally on my computer and the code inside it is trusted (say it was downloaded from a trusted github project via https). It contains import { dependency } from 'http://whatever.url/@1.0.3' with hash '6f09aa686a6263f9e992' or something like that. If an attacker replaces stuff during transfer of the dependency, then the hash won't match (assuming a collision resistant hash function). This can be transitive if the dependency also has hashes of its dependencies directly inside it (and a "only allow that" mode could enforce it). The additional benefit is that you also don't need to trust the server to not replace code for a URL under your nose from one you have previously verified. So like a lockfile, but without needing to download a separate file (because you also want verification on the first run) and a command-line argument on launch - which makes it a much more viable replacement for bash scripts (in fact, that's why I care about the ability, I wouldn't mind https-only). Am I missing something here?
- ecares 6y agoOh, I did not get what you meant ^^ well, there are still other issues than integrity with not using https.
- realharo 6y agoYeah, I'll edit the original comment to clarify that I mean hashes of dependencies.
- ecares 6y agothere are a lot of issues with using a non secure protocol to do anything over the internet, actually someone summarized the issue on the Deno issue tracker. According to them, confidentiality is also a risk. also someone could also send you garbage that would polute the memory of deno until it explode.
- DarkWiiPlayer 6y agoThat's really just a HTTP problem though, isn't it? If you use HTTP, you're exposing yourself to MITM attacks; that's on you. Is there any possible way to face this vulnerability without either 1) linking to a resource over HTTP or 2) loading a resource from someone else who linked to another resource over HTTP? Case one is the devs fault for doing it; case two is also the devs fault for not even checking their dependancies. As infrastructure grows, there will be tools that either extend the environment to block/log HTTP stuff, or catch HTTP URIs in static analysis. Both of these, specially in combination, would be more than enough.
- ecares 6y agowell, most of Deno marketing is that it is safe by default. In 2020, not enforcing a secure protocol to share source code is a no go at all. I really don't get your point here defending something that has not made any sence since the end of last decade. Knowingly leaving this kind of things in the codebase totally invalidate Deno being secure. There is not possible discussion in 2020 about https not having to be enforced. People thinking otherwise should not be allowed near a computer for their own good.
- haack 6y agoWould you say linux is insecure because a user can download an arbitrary shell script and run it? I know it's not an identical problem, but it does demonstrate that we probably agree that the onus is on the user to assess the risk of any arbitrary code they run on their machine, including the risk associated with the transport they use to obtain that code. Funnily enough I actually agree with you that I would prefer to prevent http imports by default. However doing so won't make importing a library secure, and conversely allowing it doesn't mean it is insecure. As an aside, I noticed you have posted the same one line message about the risk of a MITM attack with http imports 4 times in this thread. You might find it more helpful to contribute to the discussion by explaining why you think that.
- ecares 6y ago> Would you say linux is insecure because a user can download an arbitrary shell script and run it? Linux is not branded as a "Secure thing" right? Here Deno is building marketing on something inacurate.