Re: [PHP3] Re: [PHP-DEV] More SOAP or Dampen Thy Evangelical Fires oh Disciples

From: Date: Sat, 10 Jun 2000 06:14:05 +0000
Subject: Re: [PHP3] Re: [PHP-DEV] More SOAP or Dampen Thy Evangelical Fires oh Disciples
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-20875@lists.php.net to get a copy of this message
> If Microsoft had built Outlook securely, Malicious VBScript would be no danger > I'm no MS fan, but this is a simplistic view. Outlook could certainly be improved, but there is an essential conflict between support for applications within a scripting environment and security. The best that can be done is to try to minimize both vulnerability and impact on usability depending on the application. The Linux/Unix community has been blessed with the fact that the 'fun' target is MS. As more and more non-MS systems get out there, and as more and more other applications ride on HTTP, there will be more pressure on Linux users and Java users and everybody else. Certainly Outlook and most MS products suffer from a brittle, all-or-nothing security model, but there's lots of stuff you're using now, probably, that have holes that haven't been found yet. For instance, let's say some cool Java application becomes really popular. But the applet takes a long time to download each time, so we all download it the full version, and it has some features that require us to let it out of the sandbox a bit. Then some twit figures out that a certain object that is passed between users of this application can be perverted to evil ends, such as a worm that rides on the java app's objects and passes itself to all the other users. The best analogy I've come up with for the security issues in an active website is the FBI building in Washington DC. It is a publicly accessible building, with all sorts of nice people wandering in and out, and no doubt some not-so-nice people; and some not-nice-at-all people who would, if they could, bring a couple of pounds (1kg) of plastique and park it in the Director's office to be detonated at an appropriate time. So the folks who run the building have an ongoing problem - how to let nice people in and get to their destination (an office on the 3rd floor perhaps) with a minimum of hassle and commotion, while also detecting and preventing penetration attacks. One of the basic things done in all public buildings is to have layers of security - the front door is open during business hours. Inside is a lobby with a security guard and a directory. The elevator can take anyone to some floors, others require a certain key. Some interior doors are open during business hours. Others are locked and require a specific key; some might very well have time locks on them. Some doors require one to be 'buzzed' in. And so forth. Each 'application' has its own security model that only partly depends on the building security. Any application that doesn't is potentially vulnerable. The security guard is the firewall - it can only recognize and prevent certain very obvious threats.

« previous php.dev (#20875) next »