3 ms·
How secure are these Haskell web frameworks? (snap, happstack, etc.). Without a django and rails level of exposure, presumably they have quite a few holes stil
by sp00nman 15y ago
How secure are these Haskell web frameworks? (snap, happstack, etc.). Without a django and rails level of exposure, presumably they have quite a few holes still?
- tikhonj 15y agoI don't know about their maturity, but I think Haskell's type system and purity would help with security. It doesn't have anything like `eval` and is much less tolerant of weird input by default than dynamically typed languages (at least in my experience). Having no or limited state also helps--bad input and other mistakes tend to be more localized when they can't possibly change anything else in the program. If you're really crazy about security, then I suspect the Haskell code would also be much easier to analyze and verify.
- danieldk 15y agoAlso, many underlying components are tested using QuickCheck. QuickCheck allows you to verify that the properties of functions hold under random input. Of course, since such checking is used when the number of possible inputs is too large to check (or infinite), it is not watertight. But it helps tremendously in uncovering bugs.
- losvedir 15y agoWell, one feature that Yesod has really been focused on are type-safe URLs[1]. I imagine this would provide some level of security benefit as the framework knows "Ah, in this GET request we should have a Date, an Integer, a UserID, etc". The implementation may still have bugs, I suppose, but you can be sure that it's at least being heavily thought about. I imagine forms may work the same way, though I'm not sure about that. [1] http://www.yesodweb.com/home/snoyberg/blogs/2011/08/shakespeare/new-shakespeare-chapter.ditamap?nav=type-safe-urls http://www.yesodweb.com/home/snoyberg/blogs/2011/08/shakespe...
- joeyh 15y agoYesod also has automatic html-escaping of strings, enforced at the type level. You have to explicitly tell it when a value is raw html, to avoid XSS. It also has automatic XSRF prevention.
- SomeOtherGuy 15y agoThat's not how security works. FreeBSD has more exposure than OpenBSD, but OpenBSD is more secure. Security isn't a measure of how many people have heard of your project, it is a question of whether or not you have carefully designed your project to be secure. Haskell helps prevent a ton of errors that can cause security holes. On top of that, yesod at least has been very carefully designed to both be secure itself, and to make applications developed in yesod be secure by default. Security holes don't just magically go away when software gets popular. You should be striving to not create security holes in the first place.
- gujk 15y agoBut without extensive testing, which popularity generates, it is hard to have confidence that the striving was successful. In other words, popularity narrows the confidence interval around the measured and reported level of security.
- SomeOtherGuy 15y agoExcept that popularity doesn't generate extensive testing. IE was one of the most insecure pieces of software ever created, and was incredibly popular. People using software don't find security holes, people looking for security holes do. Has anyone with any credibility done an extensive security audit of ruby on rails? Not that I am aware of. So that puts it at the same level of confidence as snap or yesod. So then we have to judge by things like the track record, the underlying design, and the confidence we have in the developers behind the projects. None of those things are in rails or django's favor.