3 ms·
Where does the buck stop? This was simply a few layers of bad configuration. They didn't secure their database with auth/access control and they misconfigured
by DistractionRect 4y ago
Where does the buck stop? This was simply a few layers of bad configuration.
They didn't secure their database with auth/access control and they misconfigured docker.
They have a few things at their disposal:
- Using the docker-user chain to set firewall rules
- Running docker such that the default bind address for the port directive is 127.0.0.1 instead of 0.0.0.0. This puts a safety on the footgun.
- Explicitly setting the bind address of the port directive when bringing up the container.
Docker didn't come along, install itself, and open up the port. The sysadmin did. It's unfortunate they didn't know how it interacted with the firewall or how to properly configure it, but given that, should they really have been rolling it out to production systems?
They tested on prod and learned in trial by fire.
- yjftsjthsd-h 4y ago> They didn't secure their database with auth/access control True, although they had reason to believe that that was safe. > they misconfigured docker. Ah, no, that's where we disagree. They didn't configure it, docker shipped an insane default that bypasses existing security measures. There is absolutely no reason to expect that running a program in docker magically makes it ignore the system firewall.
- DistractionRect 4y agoThe sysadmin is responsible for what they install and how it's configured. Docker didn't specify what ports to open, what container to run, volume mounts, image etc. That's part of the config the sysadmin supplies when they spin it up. No matter how you slice it, it down to them not understanding what they were pushing to prod. By the same token having an unsecured database is a bad default, so we can keep passing the buck around.
- xboxnolifes 4y ago> True, although they had reason to believe that that was safe. That's like the antithesis of layered security. There would be no point in layers if you assume a single layer will protect you.