From: H. Peter Anvin Date: Tue, 18 Oct 2005 22:08:20 GMT Subject: Re: [PATCH] git-daemon extra paranoia Message-ID: <43557254.3010807@zytor.com> In-Reply-To: <4355691D.2010200@zytor.com> H. Peter Anvin wrote: > > For security, avoiding aliases is highly desirable, and if they're > useless the easiest way to do that is to reject. If aliases are > required, which it sounds like it might be, then canonicalization needs > to be applied. > > This may sound redundant, but a lot of avoiding security holes involves > applying good practices up front, instead of reactively. > I thought I might want to add a bit of an explanation, just for the purpose of illustration. Right now, we use a whitelist for access control. Aliases are not a problem, because they fail shut. A year from now, someone decides that they want a "all but" feature, and thus adds a blacklist on top of the whitelist. If aliases are permitted, unless the blacklist logic is written very carefully, one would then be able to get around the blacklist by using one of the aliased paths. Improper handling of aliases is probably second only to buffer overflows and large-string DoS attacks when it comes to security vulnerabilities. -hpa