6 ms·
This article is a bit hyprocritical. The example is an image sharing tool, but you don't resize images at all. So your server binary is tiny, but you're serv
by turtlebits 3y ago
This article is a bit hyprocritical. The example is an image sharing tool, but you don't resize images at all.
So your server binary is tiny, but you're serving full size unoptimized images and wasting bandwidth for every single user that visits the site, as well as the uploader. Even thumbnails are served full size.
In this case you're optimizing for the wrong thing.
- torstenvl 3y ago> > In this post I briefly go over the terrible state of software security, and then spend some time on why it is so bad.... The security of software depends on two factors - the density of security issues in the source code, and the sheer amount of exposed code.... It is not just the amount of code that is worrying. It is also the quality, or put another way, the density of bugs. > This article is a bit hyprocritical. The example is an image sharing tool, but you don't resize images at all. Can you explain how serving full-sized images opens up additional security vulnerabilities? I don't see the connection between your argument about bandwidth and the OP's argument about attack surface.
- turtlebits 3y agoThe author spends a lot of time on how large software has gotten, even going as far as comparing the size of their image sharing tool to another. More lines of code don't necessarily correlate to less secure - in fact, the author's tool makes a big security mistake, it doesn't strip EXIF.
- torstenvl 3y agoNot stripping EXIF metadata is not a security vulnerability. The only EXIF-related CVE I can find is in fact the opposite. https://nvd.nist.gov/vuln/detail/cve-2021-22204 https://nvd.nist.gov/vuln/detail/cve-2021-22204
- lolinder 3y agoAttack surface is about all the ways in which your software might be used to harm you or your customers. It's more than just remote code execution or DOS attacks. For many use cases stripping EXIF is a hard requirement for user privacy and security, and it's reasonable for OP to point out that cutting that out to cut lines of code would be inappropriate in many situations.
- torstenvl 3y agoPrivacy is not the same as security. They are related, but distinct. Show me the CVE that would provide any weight to the inflammatory and egregious claim that OP is a hypocrite.
- RamblingCTO 3y agoTake a breather, nobody called OP a hypocrite. > This article is a bit hyprocritical Privacy in that sense is security. Never heard of OSINT? EXIF tags are of course security relevant. /e: to make it more obvious: if I know your neighbourhood I can just blackmail you, I don't even have to hack you. I can gather information by maybe finding out your identity, getting insight into security questions and how you might answer them. I can find newspaper articles you were maybe part of etc. etc.
- xigoi 3y agoIf you put a photo with your location information on the internet, that’s your problem. It’s not the responsibility of whatever website you’re putting it on to decide for you if you want to share your location.
- RamblingCTO 3y agoYou imply that this is widely known that images contain your location, which tbh is a very disconnect assumption of the general populous.
- 3y ago
- palata 3y ago> it doesn't strip EXIF. Which is not a security issue per se, is it? If the goal of the project is to self-host it and share it with family, then keeping the EXIF may be a feature.
- geraldhh 3y ago> More lines of code don't necessarily correlate to less secure but usually it does
- Ferret7446 3y agoIt opens up the security vulnerability of your software not meeting requirements and thus users deciding instead to use other software, workarounds, and hacks.
- mixmastamyk 3y agoMiddlebrow dismissal. Author has an experimental sandbox for running imaging operations but hasn’t integrated it yet. Aka not 100% finished. Details at the site/github.