5 ms·
The author spends a lot of time on how large software has gotten, even going as far as comparing the size of their image sharing tool to another. More lines of
by turtlebits 3y ago
The author spends a lot of time on how large software has gotten, even going as far as comparing the size of their image sharing tool to another.
More lines of code don't necessarily correlate to less secure - in fact, the author's tool makes a big security mistake, it doesn't strip EXIF.
- torstenvl 3y agoNot stripping EXIF metadata is not a security vulnerability. The only EXIF-related CVE I can find is in fact the opposite. https://nvd.nist.gov/vuln/detail/cve-2021-22204 https://nvd.nist.gov/vuln/detail/cve-2021-22204
- lolinder 3y agoAttack surface is about all the ways in which your software might be used to harm you or your customers. It's more than just remote code execution or DOS attacks. For many use cases stripping EXIF is a hard requirement for user privacy and security, and it's reasonable for OP to point out that cutting that out to cut lines of code would be inappropriate in many situations.
- torstenvl 3y agoPrivacy is not the same as security. They are related, but distinct. Show me the CVE that would provide any weight to the inflammatory and egregious claim that OP is a hypocrite.
- RamblingCTO 3y agoTake a breather, nobody called OP a hypocrite. > This article is a bit hyprocritical Privacy in that sense is security. Never heard of OSINT? EXIF tags are of course security relevant. /e: to make it more obvious: if I know your neighbourhood I can just blackmail you, I don't even have to hack you. I can gather information by maybe finding out your identity, getting insight into security questions and how you might answer them. I can find newspaper articles you were maybe part of etc. etc.
- xigoi 3y agoIf you put a photo with your location information on the internet, that’s your problem. It’s not the responsibility of whatever website you’re putting it on to decide for you if you want to share your location.
- RamblingCTO 3y agoYou imply that this is widely known that images contain your location, which tbh is a very disconnect assumption of the general populous.
- lolinder 3y agoCVEs are not the be-all-end-all of information security. CVEs are usually assigned to software that is distributed, not to web-based SaaS products, social media services, or similar, which are all the places where EXIF data leaks come into play. For example, there was no CVE issued for the security flaw that leaked private information of 530 million Facebook users before 2019 [0], but that was obviously a significant security flaw. Edit: Also, regarding "privacy is not the same as security"—the line is a lot fuzzier than you think. At my org the same team ("infosec") is responsible both for the security of our products and the enforcement of rules regarding PII, because they're tightly interrelated—the main concern with security incidents is that we might lose PII. There's a reason why one of the 7 data protection principles in the GDPR is security [1]—without it there is no privacy. [0] https://www.npr.org/2021/04/09/986005820/after-data-breach-exposes-530-million-facebook-says-it-will-not-notify-users https://www.npr.org/2021/04/09/986005820/after-data-breach-e... [1] https://gdpr.eu/what-is-gdpr/?cn-reloaded=1 https://gdpr.eu/what-is-gdpr/?cn-reloaded=1
- palata 3y ago> it doesn't strip EXIF. Which is not a security issue per se, is it? If the goal of the project is to self-host it and share it with family, then keeping the EXIF may be a feature.
- geraldhh 3y ago> More lines of code don't necessarily correlate to less secure but usually it does