From: James Gray Date: 2009-07-12T05:02:36+09:00 Subject: Re: [ANN] Ruby Versions site; shell access to historical and current Rubies On Jul 11, 2009, at 2:18 PM, Caleb Clausen wrote: > On 7/11/09, James Gray wrote: >> On Jul 11, 2009, at 11:10 AM, Caleb Clausen wrote: >>> I wonder if you could say a word about security, since it's >>> obviously >>> a big concern with a service of this type... >> >> Is it? >> >> I suspect David has the EC2 image saved on S3. If you screw up his >> instance he can stop it, load a fresh copy from the S3 image, and >> move >> the elastic IP to point at the new instance. > > I assumed this was more or less the case, but it's nice to have it > stated explicitly. Yeah, I'm just worried we've gotten into the habit of always over thinking these security issues. >> It's not like you'll be stealing his data or breaking into his >> computer, right? > > I think there are still many security issues to consider. What if one > user manages to crack the root account? This attacker can then mess > the service up for other users in many subtle or not-so-subtle ways, > steal passwords, etc. So, if you steal my password to David's service, you can do what exactly? Log into David's service that you were obviously already logged into? I guess you could run Ruby 1.0 as me instead of you. Are we worried about that? As for "screwing up" the service, well, I'm not too sure what that means. Make old Ruby interpreters not run correctly? I guess I assume the tool is more for curiosity than any reliable testing service, so I didn't really feel that was a huge threat. Perhaps there are worse things they could do that I'm not imagining though. > Even without root privs, rogue users can launch attacks on other > systems. Hopefully, there's a least a log being kept. Better yet would > be to forbid network traffic altogether (other than incoming ssh, > clearly). OK, that I can see as a legitimate issue. The box could be used as a jumping off point in attacking other services. Good point there. James Edward Gray II