The Mistakes Behind Most Breaches
Nobody Chose This, Which Is the Problem
Last timeFetching What You Were Told To
The storage that is readable by anyone, the interface with the sample password, the error page listing your internals. None of these were decisions. That is exactly why they recur.
Why the default is open
A configuration finding reads as carelessness and it is almost never
carelessness. Nobody decided that the storage should be readable by
anyone. Nobody decided to keep the sample password. The characteristic
property of this whole class is that no decision was made at all, and
understanding why is what stops it recurring.
Put yourself in the position of whoever shipped the product. A new user
installs it on a Tuesday afternoon to see whether it solves their
problem. Every restriction in the default configuration is a chance for
that user to hit a wall, conclude the thing is broken or fiddly, and go
and try something else. The product that works in ten minutes gets
adopted. So the first-run path is the permissive one: listening on every
interface, no authentication, verbose errors so a confused user can see
what went wrong, generous cross-origin rules so the sample page works.
Every one of those is a reasonable choice for the first ten minutes and
wrong for the following ten years. And the ten minutes is exactly when
the configuration becomes permanent, because that is when it gets copied
into a template, committed, and forgotten.
setting | why it ships open | what has to be done
--------------------------|--------------------------|--------------------------
object storage permission | so the sample page loads | restrict, then grant
admin interface binding | so you can reach it | bind inward, require auth
initial credentials | so you can sign in | replace before exposure
error detail | so you can debug | detail to logs, not pages
cross-origin rules | so the demo page works | name the origins
transport security | so plain requests work | require it, redirect
backup permissions | so restoring is easy | match the live data
two properties they share:
each was chosen by somebody who was not
thinking about your deployment at all
each is invisible from inside the system,
because from inside everything worksThe short list that keeps recurring
It is a short list, and shortness is good news: this is a class you can
finish rather than merely reduce.
| helps a new user succeed | still helps after the fi | found by scanning from o | fixed by one setting, 0 | |
|---|---|---|---|---|
| storage readable by anyo | 1 | 0 | 1 | 1 |
| an interface open to the | 1 | 0 | 1 | 1 |
| unchanged initial creden | 1 | 0 | 1 | 1 |
| errors printing internal | 1 | 1 | 0 | 1 |
| permissive cross-origin | 1 | 1 | 1 | 0 |
| transport security not r | 1 | 0 | 1 | 1 |
| a backup less protected | 0 | 0 | 1 | 1 |
Two of these deserve a sentence more than the table gives them.
Error detail is the one people defend, because it is genuinely useful. The
answer is not less detail but a different destination: full detail to your
logs, where you can read it, and an identifier to the page, so the person
reporting the problem can quote a reference. You lose nothing and stop
publishing your internal structure, your library versions and your
queries.
A backup that is less protected than the data it copies is the purest form
of this mistake. The live store has access rules that somebody thought
about. The copy, made by a script written in an afternoon, sits somewhere
with broad permissions, and it contains exactly the same information.
Protection should follow the data, not the system that happens to hold it.
The lesson stops here
4 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents