How I hacked Digg
phoboslab.org
phoboslab.org
So digg was supposed to jump on this problem and not worry about anything else apparently.
It always seemed akin to saying
"I saw an unlocked vehicle today and I think its important that all vehicles remain locked. Since they didn't come running out when I told them to lock the car, I put it in neutral and let it roll down a hill so that they will now heed the warning"
While warning about possible vulnerabilities is helpful I have a hard time believing exploiting them is as well.
Quite frankly, yes they should. If you have an XSS hole in your web application your other user-facing security measures are worthless. If you're a social application of any sort it's even worse; you're just asking to be hit by a worm.
XSS is a Big Deal. XSS holes also really easy to find, so if a security researcher spots one it's not unlikely that a Bad Guy will find them as well.
"And then I went into the bad part of town and distributed fliers all around about how the car at the corner of Main and Screwed had been left unlocked for a while and how it had a great stereo and iPod in it."
He didn't try to act modest and he used the buzzword 'hack' which appeals more to non-technical than to technical people. Publicity stunt if you ask me.
For sure, but isn't everything on Digg a publicity stunt?
I also don't see how PHP goes 'out of its way'. It doesn't do anything, neither do most other web languages, you build or use existing frameworks and libraries to help with such tasks.
<?php echo htmlspecialchars($name); ?>
Here's how to do the same thing in Django:
{{ name }}
That's the thing that bugs me most about PHP: it's not even a productive templating language!
In any case, my intent wasn't to compare Django to PHP, it was to point out that PHP's default way of outputting things really does make it inconvenient to write secure code - hence answering the parent post that argued that poor security had nothing to do with the language used.
I realize I'm playing devil's advocate because I love Python, but you shouldn't put blame nor give credit where it isn't due.
function o($name) { echo htmlspecialchars($name); }
o($name);
<?php o($name); ?>
I've used this exact function in my own code, though I call it "h". Really sucks that we have to do this - not to mention that PHP's global namespace for functions means it's better to have long names that are more likely not to clash with third party code.
function o($name) { return(htmlspecialchars($name));}
<?=o($name)?>
which lo, and behold, looks a lot like the rails candidate below.
<%= h(@var) %>
Don't know why you inspired me to speak up.
And concerning the current problem, avoiding XSS and CSRF holes demand vigilance, especially with the many, many demands put on programmers at startups. Perhaps only with php, but I think programmers are often clever enough to work around almost any constraints, and sometimes they see security as a constraint. Digg always attracted users interested in proving their mettle by finding security holes, and as a result the developers are pretty vigilant about fixing holes.
Concerning the content of digg, well, it's an adventure ;-). As it's grown, it's left lots of room in its wake for other (maybe better) communities to develop.
I'm up to 182 and counting. I believe the subject is a total obsession with many of the "contributors" to that site.