4 ms·
I don't think this is the same issue as the exploit. The real issue was half-caught in a review on a pull request however. https://github.com/nomad-xyz/monorep
by danielvf 4y ago
I don't think this is the same issue as the exploit.
The real issue was half-caught in a review on a pull request however. https://github.com/nomad-xyz/monorepo/pull/289/files https://github.com/nomad-xyz/monorepo/pull/289/files
If this legacy enum value had been handled later in the code, there would not have been a vulnerability.
(This isn't to say that the developers were bad. The person who wrote the code was extremely knowledgeable. It's just really hard to be perfect every time. )
- bigcat12345678 4y agoNo, they are bad. They are bad because they are not competent to write the decent code required by their profession and job environment. In normal software writing trade, such engineers are called low performers and routinely managed out of any organization. Sure, the mistake is not unusual from the perspective of general software engineering. But let's not forget what software they are working on. I am totally fine with a bartender dropping a glass... I'll put a surgeon on trial if he cannot make his hands steady during a heart surgery...
- fennecfoxy 4y agoLmao, people make mistake dude. Because they're human. What is seen here is a failure of multiple people, an organisation. I remember AWS S3 went down in 2017 or so and the key point I took away from their article about it was that they didn't blame the junior dev that caused it, because it shouldn't have been able to happen in the first place. Ah here we are: https://aws.amazon.com/message/41926/ https://aws.amazon.com/message/41926/ "We are making several changes as a result of this operational event..." basically boiling down to "the employee in question is not at fault because our tools should not have let him do that".
- mhluongo 4y agoEven excellent devs make security mistakes. That's why good teams build out processes like auditing, fuzzing, heuristics checkers, and require internal peer review. This "you must be perfect" mentality is detrimental to building a security culture, IMO — no one is perfect, and the most excellent dev will slip up. Seeing the people involved in that commit, I believe that's what happened here. Hoping we learn more in the post-mortem, and they revise their practices to catch this mistake in the future.
- snypher 4y agoWhy are the bartender and surgeon held to different standards?
- xboxnolifes 4y agoThey aren't held to different standards. They are doing different work.