From: Dan Sugalski Date: 2002-01-07T14:08:29+09:00 Subject: [ruby-talk:30437] Re: snippet exchange (was: Re: Re: chomp for arrays?) At 01:25 PM 1/7/2002 +0900, Jack Dempsey wrote: >My opinion is this: anything downloaded from anywhere is suspect if you >really want to be extremely scrutinizing...what about rubycookbook? Are you >going to carefully scrutinize every line of code to make sure there's >nothign malicious in there? for small snippets sure, but as modules get >bigger, no way...what about RAA? Don't people download code from there and >use it daily? Sure. That doesn't mean it's safe. But, more importantly, they have to actively do this. >I agree that security is important, but bottom line, we're not seeking to do >anything really different here...i understand there's inherent danger in >autoloading something from the web and running it, but is it that different >from downloading, moving to a directory, then using it if you're not going >to scan through it? Security is certainly important but you'll never reach >100% safety... There is a qualitative difference here. When you explicitly fetch and install code, you at least have the opportunity to examine what you've gotten. (Whether you do or not is up to you--you can choose to take that risk) You only do it once. With a net-require, it happens multiple times, and at times that aren't under your control. Here's a concrete scenario. Assume a CGI program uses this scheme to load in part of its code. It's something useful (guestbook, weblog, web service, or something of that sort). Someone wants to compromise your system? All they need to do is attack something that's outside your control--perhaps a router, or a DNS server--and then trigger off your program. It goes off to fetch its bits (because they aren't installed locally, and at best there's a local cache that can be poisoned) and you revector them to a place of your choosing. Poof, you load up their code, and you're hosed. This also introduces a single point of failure into your system, and a point that's not under your control. Someone only needs to compromise that one point and you're compromised. Trojans have been inserted into supposedly secure repositories before and, while they're found, they're dangerous for the duration. This sort of setup, which requires periodic rather than one-off repository access, magnifies the vulnerabilities. No, the internet is *not* a safe place. (Neither are intranets--this is as dangerous or more dangerous a setup inside a corporate or university firewall than outside one) It's important to be aware of the risks something like this presents before you implement or use it. ("But that method over there is as unsafe" isn't really a good argument. Increasing your exposure is rarely a good thing to do) Dan --------------------------------------"it's like this"------------------- Dan Sugalski even samurai dan@sidhe.org have teddy bears and even teddy bears get drunk