Yes We Can. Ruby "require" over HTTP, That Is.
blog.astrails.com
blog.astrails.com
A few questions for you:
* When was the last time you personally verified gem sources that you built and installed?
* did you ever install software not from the big known sources that are verified on the OS level?
* did you ever install a gem from github (do you even know you are talking to github?)
* "wget http://somewhere/archive.tgz; tar zxf archive.tgz;cd archive;sudo make install" anyone?
* rails -m http://github.com/some_cool_template.rb?
* do you cryptographicaly sign your own sources and verify the signature during production deployments?
May be http_require is just for you. if you "failed" on any of the above, you might to be as ignorant over casual security as I am :). Security is always a tradeoff with convenience. When you consider the effort required to actually perform a man in the middle attack or some other kind of attack when you install something from github versus how hard is it to just break into your house and steal the laptop you might just decide that running some code directly from github might not be such a bad idea :)
But more importantly, the intended usage is over a secured network. vpn, ssh or ssl tunnel or even http://localhost (serving from protected directory with some ACL). I can think of many many situations where this is just 'right'.
The standard capistrano/vlad way of delivering the sources is rsync or git over ssh (or even SVN over HTTP!) How is this more secure then fetching a source over http though the same ssh tunnel (forwarded localhost, i.e. SSH -L...)?
http_require is equivalent from the security standpoint to doing 'wget ...;..;make install' and myriad other less then secure things we do almost everyday (including on production server. how did you install sphynx last time around? did you check any signatures). http_require can be used in similar ways with same security effect. saying that http_require is somehow inherently less secure then those everyday tools is somewhat hypocritical :)
[Edit: I noticed a bug. The " at the end of the URL is eaten (won't even show up in the edit box after submitting) unless there is a space there. Oops.]
require 'http://example.com/somelib.rb, '7361c1132d2ada0e987080100cfff5c1645c5e7d'
I'm also not sure this is worth an entire blog post, given how little code is required to implement it:
require 'open-uri'
module Kernel
alias :_orig_require :require
def require(mod)
mod =~ %r{^https?://} ? eval(open(mod).read) : _orig_require(mod)
end
end
Edit: I should have phrased that a little more constructively. My point was not to suggest that small snippets of code are unworthy of blog discussion; rather, it was to show that the code in question really was equivalent to any case of 'eval' applied to untrusted input. I.e., a Bad Idea.Yep! http://redhanded.hobix.com/inspect/requireThin_ice.html