Heroku Postgres Official Maintenance
status.heroku.com
status.heroku.com
I don't like how this is being handled, no matter how serious the issue. I could kind of understand what the postgres team was doing until this point where they show that while everybody is equal, some are more equal than others and get early access to security fixes.
Doing this does nothing but motivate the bad guys even more to find the hole on their own.
The initial announcement got me scared already, but this just made it worse.
Not a good precedent as far as I'm concerned.
If these are the best excuses for lack of full transparency one could could come up with, then why would anyone choose a Linux distro? Or any of the *BSDs for that matter? Transparency and an expectation of due diligence is why a lot of companies (in IT and elsewhere) still stay in business while choosing Open Source software.
Besides, Postgres isn't some run-of-the-mill startup with a dropped letter domain name. It's a venerable software foundation with almost 20 years of work and experience behind it. Which makes this a questionable course of action on their part despite the need for discretionary release.
Heroku has certainly done a lot to demonstrate how effective postgres can be practice, in addition to other contributions ).
All that being said, we don't actually know what the fix looks like, or indeed what their code looks like either right? For all we know this could be being pushed upstream? It could in some other way be unsuitable for general consumption/adoption at this time. It is possible that the fact that Heroku is going to burn it in will end up uncovering an issue or some other fact that will benefit the project, or they may be uniquely "extra" vulnerable because of deviations.
The PostgreSQL license cuts(so to speak) both ways in this case: http://www.postgresql.org/about/licence/
Heroku has things like: https://postgres.heroku.com/fork
they are a database as a service, not a distributor of software.
I'm not an expert in this field but it seems like the proper thing to do would be to announce a release date that gives everyone sufficient time to prepare and then give it to everyone.
Calling it closed source is just rhetoric. You just don't think they are moving fast enough or that there should be pragmatic reasons to give favorable treatment to any users.
And so I think it's valid to say Postgres is open source, so fix it yourself if you don't want to wait for the people who are fixing it for you for free.
Whilst it's not closed source in the traditional sense, it very much exists (there's no doubt about this) and isn't available to the general population so therefore, IMHO, is closed source.
Don't get me wrong - I understand the need to stage the release however I don't agree with the priority/privileged access.
This is also rhetoric, not to mention damaging and insulting. You know damn well that nobody can "fix it themselves." It's not known what the problem is, let alone how to fix it. For any amount of money.
It's not even about the wait time. The entire point of the embargo is that no one releases early. I initially thought this was an early release, though given that heroku uses a service model it probably isn't. The postgres team obviously cares deeply about handling this in the right way. A great many people value that, myself included.
I will be curious to know who identified the problem initially.
I don't think you're being very fair here, honestly. I doubt anyone with any kind of Postgres responsibility is intentionally leaving people exposed, or considers some users more privileged than others.
Commit access is handed out very selectively at postgresql.org, and committing patches is not the bottleneck in making features (reviewing and writing the patches is).
Typically to get that type of relationship you need to show the vendor that you have a real need for early access and that you have strong internal controls that would prevent any information gained from early access from leaking.
If the issue leaks out early or someone independently finds it they're just in that much better of a position to release the fix. Vendors will be closer to having packages ready.
Yes, it's probably not entirely fair. But there's no way to tell everyone without telling the bad guys too. The risk of telling select people to get the ball rolling is worth it if the entire ecosystem is ready when the announcement comes out.
Dealing with these issues is always going to be about managing the risk. You can't draw a line in the sand.
To some degree I don't think "full disclosure" and "responsible disclosure" are very useful terms since they have so many different interpretations.
But looking at this particular practice, I'm not sure there's been much debate in the open source world about this practice of pre-notification to vendors/large installations.
In my personal opinion I think it's absolutely necessary. Most open source users depend on binary packages provided by someone else. Unlike a closed source model when everything happens within a single company. Even then I'd be surprised if some of this doesn't happen with large customers with closed source software.
So in practice I don't think it's anything that doesn't happen with just about all heavily used pieces of software. It's just that this case happened to be more obvious this time. Largely because Postgresql closed their public repository in order to package the fix and announced that they were doing so.
Lose the sense of entitlement.
Please explain the logic here. How does Heroku getting early access provide more motivation to discover vulnerabilities?
I spotted the announcement of the postgres vulnerability and thought "sounds serious". Now I read that my production databases will be fixed as soon as the patch is available without me having to engage with the details.
60 seconds may seem like a small inconvenience but it is one still the same. I host a few clients on their servers and I need to relay this information. I sound like a jackass being that I can't give more specifics on the timing of the server being down to my clients. How does Heroku not feel the same?
I am appreciative of the update but that is also what I pay them to do.
Because they, as a hosting provider, have several orders of magnitude more clients to please than yourself. The only way to be fair to everyone is that everyone gets treated like shit (obviously embellished).
All you should be doing to CYA is telling your clients exactly why this is happening and that its Heroku, and not you, that holds the blame at this point.
The caveat would be those difficult customers (suits, exec managers, etc) that you have to handle with kid gloves. For these people... I don't think there's a graceful way to present the upcoming issue.
That said, I wonder if with the heroku postgresql setup, this vulnerability could mean that if even one db is compromised, it could allow access to other databases too. Maybe heroku runs several postgresql db's on the same virtual/physical hosts?. If that's the case, then heroku simply can't afford to let even one database stay exposed because it would risk all others.
Whether or not this is the case, I don't know, but it kinda feels like running your app on a shared-hosting account...
This would be a good chance to take a step back and think about what's more important: using Heroku or controlling your up-time?
Remember that you are running your app on a shared hosting account with Heroku.
Now, it has somewhat more isolation than a typical shared hosting account, but less isolation than using physically separate hardware.
Heroku is built on top of AWS, so your machine is running on the same physical hardware, though a different virtual machine, as other AWS customers. Furthermore, Heroku uses LXC to isolate its dynos; so you are running on the same VM as another Heroku customers, albeit separated by a container barrier. And finally, if you're using Postgres, then you're running on a shared database service, which is pretty much exactly like what you'd get with shared hosting.
On one hand, it sounds promising that they deal with important security updates, and can do it even before the fix is officially announced. Very impressive.
On the other hand, not being able to schedule the downtime to fit with your app/userbase is quite annoying. I understand this could be a potentially big security vulnerability that needs urgent fixing. But each organization is different and their risks are therefore different. Some people might prefer to take the risk of a few hours delay to apply the fix (being exposed) in exchange for not having to experience unscheduled downtime of this nature... It seems a little awkward to me that Heroku is taking this decision for its entire customer-base in such a way.
Heroku is past the point of caring about pushing the envelope, stateful routing is an infrastructure risk and overhead that primarily their least informed customers need or want.
It's a high margin operation is a low margin business, they're trying not to fuck it up.
So stop asking.
>So stop asking.
I have every right to ask and I will rightfully so. A disguised internet profile about sunglasses means nothing to me.
What, it takes place outside of linear time?
This crap is unacceptable. Even my $2.00 shared host tells me when they're going to take down my site without asking.
</speculation>