4 ms·
Hi sneak, I left a comment explaining my journey with CapRover in this HN thread. In there I explained one thing which concerned me was "netdata image in use is
by umaar 6y ago
Hi sneak, I left a comment explaining my journey with CapRover in this HN thread. In there I explained one thing which concerned me was "netdata image in use is spyware #553" which you raised last year.
I haven't yet gone through the discussion but would you mind letting me know if you're satisfied with the outcome? You appeared to be fighting for increased privacy, so thank you.
Also you'll see that in my comment, I raised another issue RE: lack of two factor auth. I'm curious, why do you think single factor auth is fine? Simply because brute force for a 30 char password is not practical on todays hardware? Or is there something I'm missing?
- kasra85 6y agoKasra here from CapRover. Regarding "netdata image": - sneak and I have fundamental differences in what we call spyware. The issue that was brought up in that thread is standard analytics events - nothing like stealing passwords or etc. - Regardless, CapRover uses NetData 1.8 [1] . According to NetData's github page, they added analytics in NetData 1.12 [2] , so even if you're concern with analytics events, this issue won't apply to you anymore. Regarding two factor auth: CapRover blocks brute-force attacks by limiting number of wrong passwords per minute. [1] https://github.com/caprover/caprover/blob/48440db14aa115aca1f458adf0480325ccc594fe/src/utils/CaptainConstants.ts#L34 https://github.com/caprover/caprover/blob/48440db14aa115aca1... [2] https://github.com/netdata/netdata#quickstart https://github.com/netdata/netdata#quickstart
- umaar 6y agoThanks Kasra, yes it seemed 'spyware' was disputed and I didn't want to jump to any conclusions. But it's good to know it's a non issue. RE: 2fa. Brute force protection is a step in the right direction, but passwords can leak in various ways, brute force isn't the only attack vector. I'll comment in the actual two factor auth discussion on the CapRover GitHub issue though.
- sneak 6y agoThe version of NetData included in CapRover is a version from before when NetData became spyware, so it’s fine. (Note that I haven’t audited it, that’s just what I’ve been told.) NetData is also optional; I use CapRover and do not opt to install it. Brute forcing a 30 char (or even 20 char) password over the network is infeasible. Do the math. Regardless, as the CapRover developer pointed out in a sibling comment, it rate limits attempts, but in the case where you are using a long, random password, it would be fine even if it didn’t.
- throwaway13239 6y agoCould you quickly explain the math behind this please? Genuinely curious
- rockland 6y agoFor every character in the password, you have 26 possible letters to choose from in an English alphabet. Brute forcing this, you would have to try every combination. Which means for a four-letter long password: 26x26x26x26 = 456 976 possible passwords. For a 10 letter long password: 26^10 = 141167095653376 possible passwords.
- sneak 6y agoYou forgot the other 26 uppercase letters, and the 10 digits 0-9. Looks good otherwise, but the result is much larger with a base of 62. Clarifying it further is “number of days to brute-force if you can try (eg) 10k requests/sec”.
- rockland 6y agoAbsolutely, you are of course correct. The uppercase letters and digits - together with the special characters like "!._-,...". I kept it to 26 letters to keep the math simpler (or rather - the numbers smaller, for myself, really). Number of days to brute-force if 10k requests/sec (26 letters still...): 4-length password = 45 seconds 10-length password = 453 years Please give me a heads up if my math is off.