You should probably be mostly thrilled about this development.
You should probably be mostly thrilled about this development.
CORS was basically ineffective in a lot of ways because it only works - by design - with newer servers that send those headers and with newer browsers that actually respect the headers and not simply ignore them. It was also ineffective for older servers from pre-CORS ages. The never break the web mentality didn't work out for this scenario.
Looking forward to this! Finally the LOIC and routersploit web implementations are ineffective. Now drop support for ftp in the web browser and we are good to go.
(̶F̶i̶r̶e̶f̶o̶x̶ ̶c̶a̶n̶ ̶s̶t̶i̶l̶l̶ ̶b̶e̶ ̶a̶b̶u̶s̶e̶d̶ ̶t̶o̶ ̶D̶D̶o̶S̶ ̶v̶i̶a̶ ̶f̶t̶p̶ ̶u̶r̶l̶s̶)̶
edit: correction: I was wrong: Firefox finally phased out ftp support this year in July.
How? They dropped FTP support a few versions ago (https://blog.mozilla.org/addons/2021/04/15/built-in-ftp-impl...).
Firefox deprecated FTP in 2015, and required it be manually re-enabled since April last year (FF88), and completely removed it in July (FF90), this year.
I was assuming that they will drop support by the end of this year, didn't follow it up recently so I missed the update in July about it.
Great. And while I blame Mozilla for much, this isn't their fault.
I almost feel as if end users should need a network license, and if they get too many tickets, no license for them!
And yes, it is not realistic.
If these clients are on Windows... tell them to use Windows Explorer.. it has FULL ftp capabilities.
You don't need a browser for ftp, or even an FTP specific program.
You cannot even uninstall or disable it as it disables the entire desktop.
Note that I am not talking about Internet Explorer (which is related, but not the same thing)
It's pretty seamless. There's lots of ftp supporting clients. Give it a go
You can insert a dozen strange answers here.
For example, one answer?
1)
A client of mine has an FTP site, and their customers access it. Those customers have an IT policy which does not allow them to install other software, for security reasons.
Thus, keeping and old version of firefox around is what their customers do.
(Yes, this is insane and bizarre beyond belief. The security policy is working against security, and the fact that the security policy doesn't care about an old browser is insane. Yet there it is.)
2)
I have a client with employees around the world. They are usually very secure. However, these employees seem to be the complete opposite of computer literate. Every step they take, every task assigned, is accompanied with PDF files and wiki walkthroughs of "here is menu item X, click this, then menu item Y", along with screenshots, and enlargements of menu items.
All their training is rote. They don't know how to use software, only how to click this, then that, as per pictures and doc, then entire report in the form that pops up.
If anything deviates -- tech support.
I honestly don't know how it is possible to find people capable of doing a job with diligence, competence, and intelligence, but require this level of hand holding, yet I see it myself, through this client, constantly.
Like I said ... strange and bizarre.
While I am sure this client will eventually manage to upgrade its staff, they have been researching clients, testing them, re-working all documentation, and even rolling out 'test upgrades' for employees!
And of course this takes time, naturally they are short staffed, and it requires management buy in at every step.
And getting people to modify about:config? That's way, waaay too complex. So they're stuck on an old browser, which they aren't supposed to use for anything but FTP, yet these employees are the sort that call a browser "google", and don't know the difference between firefox and chrome.
So you can be sure they're using an old version.
--
Again, I don't blame Mozilla for this.
This is the sort of stuff which makes me think 'maybe people need a license, like a driver's license, to be on the internet, they're too dangerous otherwise'.
But of course, as I said initially... not easy or realistic to roll out.
Now that I think of it, though, maybe it should be "businesses need a license to be on the internet". The important part here being, if you have constant breeches, and your infra gets used to launch endless attacks, you get fined until you go out of business.
This is so true. Especially since the pandemic the sheer amount of CVEs are hard to follow through and evaluate whether they're relevant for your own tech stack or not.
Would you pass on that memo to the Chrome developers, please?
It gets annoying when a page I write loaded onto my table on my LAN's WiFi cannot talk to devices I own on my LAN just because I loaded the page from my server that is on the public Internet.
PS:
> The modern countermeasure for this is to require devices parked on private networks to opt-in to the ability mix public Internet requests with private network accesses, using CORS, which is what this is about
I predict that most IoT devices won't have a way to configure this.
If the manufacturer intended it to be controllable from some web app from their site, they will opt-in to control from everyone. If the manufacturer only wants it controlled from their mobile app, they will explicitly opt-out of web control if that is possible.
That doesn't necessarily mean you connect it to the open Internet, but it means you don't leave everything inside wide open because "oh there's a firewall." It also means buggy vulnerable IoT (Internet of Targets) stuff has to be dealt with.
Firewalls are almost security theater. They're just a basic precautionary thing. Same goes for virtual and zero trust networks. Systems must be secure, period.
It's always a challenge in browser design, but basically this is just another case of killing valid use cases because some servers don't follow the spec (i.e. GETs with side effects).
There are probably 25 IoT devices in my home, and more than half of them have a magic GET request with side effects. For example, just by clicking this link, my lights turn on http://lighting.londons_explorer/cm?POWER%20ON
A malicious web page could redirect me to that URL and force my lights on with no input from me. I bet some of the devices allow firmware updates with the same method.
Oh, I know! How about a browser that does not allow direct navigation from external to internal addresses? Ah, wait.
It still does not quite work for services that have a public IP address. So where do you go from there, a new protocol that has capability handling and external access is disabled by default?
Forcing companies to issue recalls for buggy hardware and firmware could probably do the trick. Note the expense and the fact of insufficient dissemination of found issues combined with lag to fix them.
In the meantime Google can single handedly monkey patch this situation within a few months and force manufacturers to catch up with the next product cycle. While a less ideal route, this seems far likelier to produce actual results within our lifetimes.
I think it’s because when stuff works it looks simple. There isn’t an obvious difference between a mound of dirt piled up in days and one that’s carefully compacted as it’s constructed. At least until you want to build something on top that actually lasts for 50 years. Build stuff to last takes time and nobody is around to see you succeed.
Back to your point actually fixing the underlying issues with IOT security is worth it long term even if it hypothetically takes 20 years to get it correct. At the same time moving quickly and patching one of 100,000 problems can still be useful.
What are some recent examples? Especially dealing with technology?
I can think of a bunch of counter-examples where the government did not do a good job of regulating:
* Rural broadband failed
* Net neutrality failed
* Healthcare.gov was a fiasco
* Wireless spectrum auction never got us municipal/rural long-range wireless
* NASA's duties have largely been outsourced to private actors
* State DMVs are a shitshow
* Election integrity failed
* They can't figure out what to do about online disinformation
* Warrantless wiretapping: both unconstitutional yet ineffective, as in 9/11 and the lack of data sharing between agencies
* Foreign military misadventures, our traditional forte: Afghanistan, Iraq, both abysmal failures
* Healthcare: a joke compared to every other developed country
* Education: pathetic and getting worse
* Social programs: Welfare, what welfare? inequality and homelessness getting worse every year
* Infrastructure: crumbling
* Clean water: only for rich white people
* Immigration: heh
* Covid: lol
* Renewables: haha
* Nuclear: let's pretend it's not there
On every major policy front, the US government has been a disaster for decades. I'm no libertarian by any stretch, but our government is a complete shitshow compared to any other developed democracy. We have neither the leadership competence (decisionmakers and legislators) nor the engineering talent (career civil servants) who can tackle something as diverse as nuanced as IoT security, or arguably, digital security in general. Give them 20 years and they might be able to catch up to 1990s netsec, and by then the manufacturers will be two decades ahead and foreign intelligence services even further beyond that.
Our government is doomed, and taking us down with it.
Of course it’s all stuff the government does directly like GPS that generally works even if theirs issues with version 1. Go to Healthcare.gov today and it works fine, but wow 8 years ago there where issues. People still get mileage talking about that launch presumably because it’s that unusual.
Bringing up the FTC there’s keeping the wireless spectrum clean. You can blame the Government for not solving all shorts of issues, but people complain while at the same time they largely don’t want state or federal government internet. Healthcare is the same issue, we apparently don’t want even a public option, yet somehow the government is still on the hook.
People are always going to talk up government boondoggles because that’s what’s memorable. Clean water in all 155,693 public water systems in the United States isn’t easy it’s a monumentally difficult task that works 99.9% of the time across a huge range of public and private organizations managed by a huge range of different locations from tiny towns to vast cities. Of course if people actually trusted their water then bottled water would be less popular…
Those things you mentioned aren't recent developments. Yes, there was a time when our government was capable of producing good output. What happened? Why are we still judging today's government by its successes of decades past...? Most of what you mentioned is literally last-century tech. The world has moved on; our government has not.
> You can blame the Government for not solving all shorts of issues, but people complain while at the same time they largely don’t want state or federal government internet.
Maybe there's one class of issues that government can't deliver on because the public mandate isn't quite there yet, like single-payer healthcare. But there's another class of issues that the public DOES want, the government already wrote the laws and allocated the budget for, and then did absolutely nothing about (like rural broadband grants basically going to corrupt telcos, with zero real enforcement). That has nothing to do with the lack of public will, just sheer incompetence and corruption.
Then there's the outright unconstitutional things, like warrantless wiretapping or drone assassinations of US citizens... to say nothing of recent developments, like Roe v Wade.
It's not that our boondoggles our more visible, it's that we fail at providing basic services for a huge portion of the population -- things that most other developed democracies can provide without much issue or controversy. By that measure, we fall far short.
Also when you excluded say Nigeria and in fact most counties then every remaining country is going to seem worse simply because you just arbitrarily raised the standards. It’s not US exceptionalism to simply say few countries or groups of countries have landed anything on Mars which is freaking difficult. Sure, providing great healthcare is more important, but it’s also something very few counties have done well.
In the detracting from success by looking at unrelated failures misses my argument, at best it speeks to the likelihood of success not the possibility.
So what do you think is a fairer way to measure governments? Ratio of important successes to important failures? A matrix of weighted policies and implementation scores?
You'd probably end up with something similar to to the UN's human development index (http://hdr.undp.org/en/composite/HDI), in which the US ranks #17, behind Norway, Ireland, Switzerland, Hong Kong, Iceland, Germany, Sweden, Australia, Netherlands, Denmark, Finland, Singapore, the UK, Belgium, New Zealand, and Canada. All of those are perfectly livable countries. My only criterion was "developed democracies", and Hong Kong isn't even much of a democracy anymore. I don't think that's an unreasonably high bar.
Our government is just on the low end of mediocre compared to other developed democracies, at least by the metrics I can think of.
If you can think of a better metric, I'm all ears.
https://developer.mozilla.org/en-US/docs/Glossary/Idempotent
> DELETE /idX/delete HTTP/1.1 is idempotent, even if the returned status code may change between requests:
So requesting to open the garage door multiple times which results in an open garage door in the end is an idempotent request, even though after the second request the response is "I am already open!"
Now, a request to toggle the state of the garage door would not be idempotent. The state of the system is different if you call it an odd or even amount of times.
Not quite. If a GET request is side-effect free then it won't be logged (since that is a side effect).
GET requests aren't supposed to modify state. Logging is a side-effect but it isn't usually considered to be stateful. Changing the state (on/off) of a lightbulb is definitely against the standard requirements for a GET request.
Perhaps a better way to express this is that user agents are permitted to turn one GET request into N GET requests (N >= 1), and can also issue GET requests without user interaction (e.g. for preloading). When this happens the system should still meet its (customer / end-user) requirements. The requirements related to logging are that every request is logged, so it makes sense to record each GET request separately. The requirements for the light bulb are that one user interaction (not one GET request) equals one state change, so updating the state in response to each GET request doesn't meet the requirements. Even if the API were explicitly "turn on" or "turn off" rather than "toggle" you still wouldn't want the state to be affected by preloading, and you could get odd results if opposing requests were repeated (interleaved).
edit: what I can see breaking is stuff like Synology QuickConnect https://global.download.synology.com/download/Document/Softw...
Of course this has the downside if you have actual 'internal only' stuff, but those could be separated from the split stuff... Just too much work with years (decades) old setups?
So it doesn't solve anything here.
If an organization is using the "BeyondCorp" approach, it doesn't seem relevant, but that's tough to bolt onto large, complex existing environments IMO.
Edit: just to clarify, the advantage is similar to what "BeyondCorp" gets you - end users just need to remember the one URL, regardless of where they're connecting from.
I have about two dozen devices on my private LAN so I wouldn't consider myself to be "big" or "enterprise".
The setup is fairly unusual though because most users (and unfortunately many developers) lack the technical know-how for it.
Goooooood. I hate this thing with a passion since I had to set it up for a computer illiterate friend.
> just by clicking this link, my lights turn on
Wasn't working for me, so I added an entry to my hosts file directing it to 127.0.0.1.Now I don't know what's happening with _your_ lights, but when I click that link my own lights come on.
(Cracked a localhome joke in for my first IT job interview. Manager laughed, Engineering Manager rolled his eyes.)
Even this measure by Chrome is extremely limited, as it sounds like they're only blocking insecure (HTTP) sites from making requests to your private network. HTTPS sites are unaffected (for now).