3 ms·
Generally: don't trust anything from the outside world or anything that can transit untrusted infrastructure, that means check types and sanitize values before
by midas007 12y ago
Generally: don't trust anything from the outside world or anything that can transit untrusted infrastructure, that means check types and sanitize values before passing along. Break loudly and quickly to get attention for a fix. Keep the codebase as tiny as possible too.
Ruby: recompile with minimized OpenSSL 1.0.1+ (LibreSSL when possible) and with patches that improve Ruby's default OpenSSL security.
https://gist.github.com/steakknife/8228264 https://gist.github.com/steakknife/8228264
https://gist.github.com/steakknife/10092587 https://gist.github.com/steakknife/10092587
https://gist.github.com/steakknife/10096008 https://gist.github.com/steakknife/10096008
For Rails apps: use brakeman as one part of security audit strategy
For gem authors, sign them (please!): I wrote waxseal to make it dead simple
[sudo] gem cert --add <(curl -L https://gist.github.com/steakknife/5333881/raw/gem-public_cert.pem) # adds my cert (do once)
[sudo] gem install waxseal --trust-policy HighSecurity
For gem users, find which aren't signed
Add this to ~/.gemrc gem line:
--trust-policy MediumSecurity
or just if there's no gem: .... already:
gem: --trust-policy MediumSecurity
For anyone using git, sign your tags (git tag -s ...) and commits (git commit -S ...) por favor
- InAnEmergency 12y agoFor what it's worth, --trust-policy has been broken since RubyGems 2.0.0 and will not be fixed until 2.3: https://github.com/rubygems/rubygems/issues/859 https://github.com/rubygems/rubygems/issues/859