Loss of Innocence
Posted: 27 January 2006 02:54 AM   [ Ignore ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  08-05-2002

It finally happened.  After nearly two years and 192,000 lines of code, ExpressionEngine got its first security bulletin.  Damn.

This morning I was incredibly angry, not only at myself for letting something slip through, but also because when the exploit was found it was never brought to our attention.  Instead, it was reported to a security site where not only was the information incorrect and misleading, but it was copied among other security sites without being confirmed.  We only learned about it after a new member registered and mentioned it in the bug forum.

continue...

 Signature 
Profile
 
 
Posted: 27 January 2006 03:29 AM   [ Ignore ]   [ # 1 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  13106
Joined  05-15-2004

OK, just a quick thought on the situation: Well, it had to happen. As you so aptly put it: “No matter how many eyes or how many skilled professionals examine a program, there will be something missed”. So, the question is not: “Can you make your code 100% secure?” (you can not) but rather “How do you handle such a situation?”

As we all know, security is a process. With that in mind, I am impressed by the way pMachine handled this. I mean, you had a bugfix out and ready for download the day you were notified of the bug (and you can’t be blamed that no vendor notification prior to publication took place.)

I for one am thankful for such resposniveness.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 27 January 2006 06:02 AM   [ Ignore ]   [ # 2 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1401
Joined  01-15-2005

Well at least 2 years is still a record for a CMS.

We only learned about it after a new member registered and mentioned it in the bug forum.

I was not following, which thread was that?

 Signature 

EE Duration Tags | {view_count_total}

Profile
 
 
Posted: 27 January 2006 06:07 AM   [ Ignore ]   [ # 3 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  13106
Joined  05-15-2004

It was closed, and now appears to have been removed altogether. I spotted it early on and asked Paul in a PM about it. Basically, it consisted of copy & pasting the exploit, but it’s significance was not immediately obvious at the time.

PS: Is Rick in a bad mood or what? Who can blame him…

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 27 January 2006 01:23 PM   [ Ignore ]   [ # 4 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  7534
Joined  08-05-2002

Yes, the thread was closed because it simply contained a copy of a copy of the original warning, which itself was inaccurate and incorrect.  We felt it was better to actually correct the contact poster of the warning, correct the security sites, and post our own news blurb with fix instead of leaving the topic with bad information available.  Sort of the one voice approach.

Rick has been burned by these security sites before and considering the rude and negative email I got from Secunia this morning, I know there are a number of bad apples out there who really do not care about the software and protecting customers, but more about their own services.

 Signature 
Profile
 
 
Posted: 27 January 2006 02:17 PM   [ Ignore ]   [ # 5 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1401
Joined  01-15-2005

Hakuna Matata! Don’t Worry, those sites are inseparable parts of the World Wide Web. Who cares about them?

 Signature 

EE Duration Tags | {view_count_total}

Profile
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 10:33 AM
Total Registered Members: 61054 Total Logged-in Users: 25
Total Topics: 73861 Total Anonymous Users: 13
Total Replies: 398394 Total Guests: 458
Total Posts: 472255    
Members ( View Memberlist )