4 ms·
What software are they using for their forums? It seems like you're just begging for this to happen to you if you go with any of the open source options. They a
by coderdude 14y ago
What software are they using for their forums? It seems like you're just begging for this to happen to you if you go with any of the open source options. They all eventually have exploits available for them (some have them all the time). As long as you know what you're doing you should always cook up your own solution for this sort of stuff even if what you come up with lacks features. One day you might be hacked by someone clever who figured out a weakness in your implementation, but at least it won't be a script kiddie with some automated method of attack.
- lumberjack 14y agoBut can't you say that for every web technology or are forums software especially bad security wise?
- coderdude 14y agoThis probably applies to any type of software online that has user accounts. Forums seem to get hit more than most other things because of the concentration of email/password combos.
- deleted 14y ago[deleted]
- mavroprovato 14y agoThis is a classic argument against open source, but security through obscurity never works. If you want to keep safe from script kiddies, always keep your software up to date.
- jvdongen 14y agoKeeping your software up to date is great advise. However I do not entirely agree with the statement that security through obscurity never works. It can never work alone - true. But in combination with other measures it can be a great help. And with respect to the point cshimmin makes, there is some merit to it. Yes nearly every piece of software, open or closed source is bound to have vulnerabilities. However, the chance of someone taking the time for finding and exploiting a moderately hard to find bug (not referring to a run-of-the-mill sql injection) in a piece of software I've written myself and I'am the only user of is vastly lower than in case of a popular piece of open source forum software (to some extend depending on who I - the only user - am of course).
- ibotty 14y agounless, of course, you are vulnerable to a certain class of attacks (e.g. the ruby on rails attack this year). the chance that others have already fixed it is way better when more people use the same software. i'm not subscribing to the "enough eyeballs, all bugs are shallow"-argument, but the opposite is also wrong. deeply wrong.
- coderdude 14y agoIt's really not intended as an argument against open source. It's an argument against using open source forum software (maybe even open source web app software with user accounts). There are always exploits available and you can't always patch in time. Sometimes there isn't even a patch available before the exploits are in use. I was always taught never to rely on security through obscurity. I understand that it's a best practice to not. But feeding off of what jvdongen said, you are far less likely to be hacked using well-constructed homebrew software than an off-the-shelf open source solution.
- blackhole 14y agoAll this does is guarantee you do it wrong.
- coderdude 14y agoCan you make a case for why this is so? Not everyone fails at security. Just because one person is working on the software and because that software is not open source does not mean that you will leave something in your software that can be exploited in a way that gives someone access to your database.
- Jach 14y agoWhether your site gets owned or not is dominated by its popularity rather than its source code license. There's a number of proprietary forums out there too, they tend to suck as much as the open variants. (And if it's for sale, your attacker has a copy.) Being custom-developed protects you from the script kiddies (but you'll have to fight spam yourself--fortunately custom non-OCR-requiring captchas can have higher blocking success rates than even recaptcha), being closed gives you little more than a time advantage if you do become popular. Security through obscurity is a real security layer, it's just incredibly thin. The better argument for "roll your own", if you have the time, is that it can be a great learning experience. But regardless of what's used, if you ever do get popular enough to become a conscious target it's just negligent to not do security audits from people whose job is security. It's also helpful to design from the perspective of "everything is compromised, what will I regret."
- coderdude 14y agoThis is very sound advice. On a long enough timeline everyone gets hacked. You should definitely spend the money to get audited by professionals.