ContentsThe library

The Mistakes Behind Most Breaches

Nobody Chose This, Which Is the Problem

Last timeFetching What You Were Told To

The storage that is readable by anyone, the interface with the sample password, the error page listing your internals. None of these were decisions. That is exactly why they recur.

Why the default is open

A configuration finding reads as carelessness and it is almost never

carelessness. Nobody decided that the storage should be readable by

anyone. Nobody decided to keep the sample password. The characteristic

property of this whole class is that no decision was made at all, and

understanding why is what stops it recurring.

Put yourself in the position of whoever shipped the product. A new user

installs it on a Tuesday afternoon to see whether it solves their

problem. Every restriction in the default configuration is a chance for

that user to hit a wall, conclude the thing is broken or fiddly, and go

and try something else. The product that works in ten minutes gets

adopted. So the first-run path is the permissive one: listening on every

interface, no authentication, verbose errors so a confused user can see

what went wrong, generous cross-origin rules so the sample page works.

Every one of those is a reasonable choice for the first ten minutes and

wrong for the following ten years. And the ten minutes is exactly when

the configuration becomes permanent, because that is when it gets copied

into a template, committed, and forgotten.

FIG 1The list that accounts for most configuration findings
plaintext
setting                   | why it ships open        | what has to be done
--------------------------|--------------------------|--------------------------
object storage permission | so the sample page loads | restrict, then grant
admin interface binding   | so you can reach it      | bind inward, require auth
initial credentials       | so you can sign in       | replace before exposure
error detail              | so you can debug         | detail to logs, not pages
cross-origin rules        | so the demo page works   | name the origins
transport security        | so plain requests work   | require it, redirect
backup permissions        | so restoring is easy     | match the live data

two properties they share:
  each was chosen by somebody who was not
  thinking about your deployment at all

  each is invisible from inside the system,
  because from inside everything works
Seven rows, and the middle column is the whole explanation of the class: in every case the open setting is the one that makes a new user successful on the first afternoon. The right column is what somebody has to do, deliberately, afterwards.

The short list that keeps recurring

It is a short list, and shortness is good news: this is a class you can

finish rather than merely reduce.

FIG 2Who each default helps, and who finds it
helps a new user succeedstill helps after the fifound by scanning from ofixed by one setting, 0
storage readable by anyo1011
an interface open to the1011
unchanged initial creden1011
errors printing internal1101
permissive cross-origin 1110
transport security not r1011
a backup less protected 0011
The second column is almost entirely zero, which is the argument for closing all of them: the benefit expired long ago and the exposure did not. The two marked cells are the exceptions worth knowing. A loosely protected backup never helped anybody, and cross-origin rules take more than one setting to get right.

Two of these deserve a sentence more than the table gives them.

Error detail is the one people defend, because it is genuinely useful. The

answer is not less detail but a different destination: full detail to your

logs, where you can read it, and an identifier to the page, so the person

reporting the problem can quote a reference. You lose nothing and stop

publishing your internal structure, your library versions and your

queries.

A backup that is less protected than the data it copies is the purest form

of this mistake. The live store has access rules that somebody thought

about. The copy, made by a script written in an afternoon, sits somewhere

with broad permissions, and it contains exactly the same information.

Protection should follow the data, not the system that happens to hold it.

The lesson stops here

4 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01One Mistake, Wearing Different Clothes
  2. 02The Caller Is Not Running Your Softwareopening only
  3. 03The Most Common Serious Finding There Isopening only
  4. 04Follow It From the Field to the Place It Runsopening only
  5. 05Your Server Can Reach Things Nobody Outside Canopening only
  6. 06Nobody Chose This, Which Is the Problemyou are here
  7. 07Most of What You Ship, You Did Not Writeopening only
  8. 08Could You Reconstruct It Afterwardsopening only

Read alongside