3 ms·
> In gitlabs case this is much less relevant (...) Why, though? GitLab is often self hosted, so being able to iterate through objects, like users, can be usefu
by serial_dev 3y ago
> In gitlabs case this is much less relevant (...)
Why, though? GitLab is often self hosted, so being able to iterate through objects, like users, can be useful for an attacker.
- remus 3y agoYou're right, fair point.
- yellowapple 3y agoIn my experience self-hosted GitLabs are rarely publicly-accessible in the first place; they're usually behind some sort of VPN. As for an attacker being able to iterate through users, if that information is supposed to be private, and yet an attacker is getting anything other than a 404, then that's a problem in and of itself and my energy would be better spent fixing that.
- Anon1096 3y agoThis is again a defense in depth thing. In the age of WFH, cracking a corporate VPN is really not that difficult. If you can make an attacker's life harder for low cost you should do it just in case.
- yellowapple 3y agoExcept you ain't really putting up a meaningful obstacle against an attacker here. Compared to the typical effort of cracking a corporate VPN, brute-forcing IDs is downright trivial. Like I said elsewhere: it's like calling ROT13 "defense in depth".