4 ms·
'Connect to an existing node' is likely implemented using ERTS (http://erlang.org/doc/reference_manual/distributed.html http://erlang.org/doc/reference_manual/d
by wrren 5y ago
'Connect to an existing node' is likely implemented using ERTS (http://erlang.org/doc/reference_manual/distributed.html http://erlang.org/doc/reference_manual/distributed.html). So you're basically connecting to the runtime of the target node. The security model for ERTS isn't great, though, so your point stands. All you need is a matching secure cookie and you can connect and run any commands you want.
- qbasic_forever 5y agoYep, and then the temptation to fix it is to roll your own homebrew auth over websockets... which is super risky.
- dnautics 5y agoI imagine that such a solution would be a public package/extension with eyes on it.
- lostcolony 5y agoTo put context on that - it's still TLS, the cookie is just a password. The problem is that it's one password for the node network, and you either have it, or you don't. So there's no real administrative control over access; it's shared password.
- qbasic_forever 5y agoAnd a browser can be tricked into sending the cookie if you accidentally misconfigure the server. You will have no indication or warning of this happening, from either the client or server side, if you get it wrong.
- lostcolony 5y ago>> if you accidentally misconfigure the server Sure, but I mean...
- gallexme 5y agoIf u use live book to print the erlangs distribution cookie, u still would need to steal the inter nodes certificate and be on the server network to do any shenanigans But how would u get into livenotebook in first place if u shouldn't have access to the container it and the connected nodes run on? I mean u can easily destroy a production system with couple erlang commands