4 ms·
Aren't these equivalent, given that the /proc/x/environ file exists?
by photon12 6y ago
Aren't these equivalent, given that the /proc/x/environ file exists?
- joosters 6y ago/proc/x/environ is similar, but has more restrictive permissions: user-readable only, whereas /proc/x/cmdline is world-readable.
- photon12 6y agoFair point. Though I feel like in any modern app deployment scenario that isn't going to be a meaningful defensible boundary. The answer is to use neither, especially given the number of times I've used a path traversal vulnerability to expose /proc/self/environ on a pentest, and the one time I was frustrated on a pentest when every app in the environment used a dedicated API for secret retrieval and the path traversal vulnerability I had access to was worthless.
- imtringued 6y agoHow do docker secrets solve the problem then? According to the article they store the secret in a file as well. You could access the docker secret just as easily as environment variables. The only meaningful difference is that /proc/self/environ will return all secrets at once meanwhile with docker secrets you have to know the file path.
- photon12 6y agoThey don't There's a lot of bad advice on secret storage that is Not Based On A Threat Model™