5 ms·
Bug #9424: ruby 1.9 & 2.x has insecure SSL/TLS client defaults
- steveklabnik 13y agoThere's been a lot of anger around Twitter on this. I've also seen a lot of people cherry-picking a non-native speaker's words out of context too. Specifically, "Ruby is not a project for security." That doesn't mean that this bug is not important, or that the Ruby team's decision as it currently stands is a good one. But it's a complex issue.
- coherentpony 13y agoIf someone gave me that sentence, I wouldn't know whether the person that wrote it was a native speaker or not.
- steveklabnik 13y agoExactly. And it implies something different than what was meant if you read the surrounding context.
- insecure_ruby 13y ago"It's a complex issues" == Ruby Security Fails again. It is a crackers dream that so much Ruby code is being exposed to the web these days. Such low hanging fruit. Even the script kiddies laugh at the ease of compromise. Sigh.
- steveklabnik 13y agoA throwaway troll account, how novel.
- tptacek 13y agoThe SSL2 ClientHello thing is, IIRC, also a compat hack; Firefox used it (at least until recently) when it connected through proxies.
- briansmith 13y agoFirefox stopped using it on 2011-08-16. If you've seen Firefox using it recently when connecting through proxies, please let me know.
- tptacek 13y agoI'm sure you're right. It was on whatever version of Firefox was on my work laptop the week I learned Golang, since my first project with the language was an HTTPS/SSL proxy. I even griped about it on Twitter (it breaks Golang's crypto/tls), and (after we'd hacked support for it into our local tree) got a link to a patch. That would have been... meh... a year and a half two years ago.
- state_machine 13y ago"Ruby is not a project for security." That's from ruby-core. That's a frightening attitude for a project to take.
- dperfect 13y agoDid you actually read the context of that quote, which happens to communicate almost exactly the opposite of what you're inferring (and implying by quoting it out of context)?
- dudleyf 13y agoFrom the context, it seems like mame was trying to say that Ruby is not a security-focused project, so the core team has not attracted many volunteers who are familiar with SSL/TLS. I inferred from this not that Ruby team doesn't care about security, but that they lack the expertise to handle it properly. They're aware of that, and choose to leave these decisions up to the experts. It's a reasonable position, but, as a user, "We don't know how" doesn't help me any more than "We don't care".
- state_machine 13y agoSure, the context of the thread is that ruby-core is reluctant to start changing OpenSSL defaults because Security is Hard, the ruby team is volunteers who might not have expert-level crypto understanding, and and you risk doing more harm than good if you mess with crypto when you do not know what you're doing, so they'd rather leave OpenSSL's defaults alone, and let OpenSSL, written and reviewed by security focused people, fix any issues (I think this is a fair summary?). While these are valid concerns, you can't wholly pass the buck to OpenSSL and to people installing a new version of OpenSSL and re-linking ruby against that -- ruby project should should always ship the most secure ruby possible, all the time. Newer OpenSSL has already changed these defaults, smart people who know what they are doing have already agreed and documented that this is a good idea, and ruby is only hurting their users by dodging responsibility. edit: spelling.
- dperfect 13y ago
- lobster_johnson 13y agoAnyone know of a simple recipe to set up secure defaults?
- pixl97 13y agoThis is a good place to start on good OpenSSL defaults. https://www.ssllabs.com/projects/best-practices/index.html https://www.ssllabs.com/projects/best-practices/index.html
- ces1 13y agoNon-SSL expert here and first time poster (not trolling). Python also uses a wrapper for OpenSSL and has similar issues with default settings. Is this problem specific to Ruby or also Python apps as well?
- sanxiyn 13y agoThis also applies to Python. For example, Python recently disabled SSLv2. Someone filed a bug and the fix was committed within 3 hours. http://bugs.python.org/issue20207 http://bugs.python.org/issue20207
- girvo 13y agoSo does PHP, though this is fixed in 5.5 IIRC.