Re: [PHP3] Re: [PHP-DEV] More SOAP or Dampen Thy Evangelical Fires oh Disciples
| From: | Gary Bickford | Date: | Sat, 10 Jun 2000 06:14:05 +0000 |
| Subject: | Re: [PHP3] Re: [PHP-DEV] More SOAP or Dampen Thy Evangelical Fires oh Disciples | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-20875@lists.php.net to get a copy of this message | ||
> If Microsoft had built Outlook securely, Malicious VBScript would be no danger
>
I'm no MS fan, but this is a simplistic view. Outlook could certainly be
improved, but there is an essential conflict between support for applications
within a scripting environment and security. The best that can be done is to
try to minimize both vulnerability and impact on usability depending on the
application.
The Linux/Unix community has been blessed with the fact that the 'fun' target is
MS. As more and more non-MS systems get out there, and as more and more other
applications ride on HTTP, there will be more pressure on Linux users and Java
users and everybody else. Certainly Outlook and most MS products suffer from a
brittle, all-or-nothing security model, but there's lots of stuff you're using
now, probably, that have holes that haven't been found yet.
For instance, let's say some cool Java application becomes really popular. But
the applet takes a long time to download each time, so we all download it the
full version, and it has some features that require us to let it out of the
sandbox a bit. Then some twit figures out that a certain object that is passed
between users of this application can be perverted to evil ends, such as a worm
that rides on the java app's objects and passes itself to all the other users.
The best analogy I've come up with for the security issues in an active website
is the FBI building in Washington DC. It is a publicly accessible building,
with all sorts of nice people wandering in and out, and no doubt some
not-so-nice people; and some not-nice-at-all people who would, if they could,
bring a couple of pounds (1kg) of plastique and park it in the Director's office
to be detonated at an appropriate time.
So the folks who run the building have an ongoing problem - how to let nice
people in and get to their destination (an office on the 3rd floor perhaps) with
a minimum of hassle and commotion, while also detecting and preventing
penetration attacks.
One of the basic things done in all public buildings is to have layers of
security - the front door is open during business hours. Inside is a lobby with
a security guard and a directory. The elevator can take anyone to some floors,
others require a certain key. Some interior doors are open during business
hours. Others are locked and require a specific key; some might very well have
time locks on them. Some doors require one to be 'buzzed' in. And so forth.
Each 'application' has its own security model that only partly depends on the
building security. Any application that doesn't is potentially vulnerable.
The security guard is the firewall - it can only recognize and prevent certain
very obvious threats.