4 ms·
If I were designing a system like this, I would not trust clients to perform legitimate analysis nor report legitimate results.
by morley 4y ago
If I were designing a system like this, I would not trust clients to perform legitimate analysis nor report legitimate results.
- causi 4y agoWhat? But you're the one writing the client.
- sofixa 4y agoDoesn't matter. Never trust the client - it's outside of your control, it can be patched, it can be hacked, it can be spoofed, etc.
- BoorishBears 4y agoLittle understanding: Undying trust of the client Dunning-Kruger level of understanding: Never trust the client for anything ever, it's unreliable, everything must be off client. Never mind the client is literally the interface into your system, so it being compromised is already game over for an application where the user is most vulnerable party you wanted to protect... Deep understanding: Trusting the client requires a well thought out security model. If the client is hacked in this case, they already have full control over what the user sees, they can cut out your remote check. Maybe a good balance would be to hash the root of the URLs and compare those, or use fuzzy hashing on page contents, just so that the backend isn't getting a bunch of private urls that might accidentally get logged somewhere. Trades detecting stuff hidden behind redirects for less liability on your backend, something to possibly consider depending on functional requirements.
- shepherdjerred 4y agoIt sounds like you’re advocating for no client at all
- Spivak 4y agoJust as a trivial example, how confident would you be in this auth scheme? 1. User opens Outlook and types in their email and password. 2. The app requests the user's password hash from the server and checks it. 3. Outlook tells the server auth was successful and gets a session token.
- shepherdjerred 4y agoIn this example you're right. For something like scanning a site for malicious content, on-device is not a bad approach. It decreases the amount of data sent to the server. The client has a much bigger issue to worry about if the client-side malware scanning has been compromised. Malware could modify the UI/network calls such that your server-side scanning displays a positive result anyway. You have to trust the client to display information to the user at some point. Link malware scanning that job can safely be delegated to the client. Authentication cannot.
- gnubison 4y ago… but it doesn’t matter if the client is compromised, because all it would hurt is the user, right? If the client was compromised, it could just not send anything to your servers, or ignore the results, or …