How is this different than other HN beloved products like Drupal or pretty much any CMS? I can't think of any single one that has proper sandboxing. OwnCloud is just a type of CMS really, but instead of managing HTML, it manages all sorts of filetypes.
e.g. http://www.cvedetails.com/vulnerability-list/vendor_id-26/pr...
Pretty much everything is insecure. Writing things in not-php isn't the magical fix you seem to think it is.
The linux kernel has 16 million lines of code, Wordpress has 300k.
Yet Wordpress[1] has had nearly as many security vulnerabilities as the kernel[2]; 194 vs 257 exploits.
Wordpress is one of the most exploited software packages ever created. It is the textbook example of bad programming.
Just mentioning the kernel when talking about Wordpress is pretty ridiculous.
[1] http://www.cvedetails.com/vulnerability-list/vendor_id-2337/...
[2] http://www.cvedetails.com/vulnerability-list/vendor_id-33/pr...
Hyperbole much?
It's one of the most popular software packages installed on the web. It's not surprising it has a lot of eyes on it.
Dozens of other packages have a much larger install base than Wordpress.
Wordpress has 32(!) CVE's tagged with "Exec Code" (remote code execution) alone. The last one a mere 6 months old.
If you know another project that comes even remotely close to that then I'd be genuinely curious which one that would be?
Yeah, it does. You can write a crappy piece of software that nobody uses and because nobody has interest in it, it has no known security issues! Big deal.
I'm not saying that Wordpress has a great code-base or that there's no correlation, but that popularity is a substantial variable in that equation.
> Dozens of other packages have a much larger install base than Wordpress.
Name one web based software suite that's installed more often.
What does "web based" have to do with anything?
Do you think SSH, Postfix, nginx, Apache & Co don't get the same amount of scrutiny? Each of them has a significantly larger install base than Wordpress.
NO! Because they're behind a firewall AND each operates on a very restricted protocol! It has nothing to do with quality of codebase. If Wordpress was behind a firewall and only restricted to text-based input per spec, you wouldn't find many vulnerabilities either.
> What does "web based" have to do with anything?
Because "web based" is the client. It has to be flexible and with flexibility, comes complexity, and with complexity come exploits.
Try getting a CRM going on Postfix or all the myriad other things Wordpress is being used for.
Huh? SSH, Postfix and nginx are usually not firewalled.
Because "web based" is the client. It has to be flexible and with flexibility...
If "flexibility and complexity equal vulnerability" then why does the linux kernel, 53x the size of Wordpress and a tad more complex than a CMS, not have about 53x more exploits?
And why does no other CMS system or framework come even close to the number of critical vulnerabilities in Wordpress?
Because no other CMS or framework has as many deployments. Not even close.
> If "flexibility and complexity equal vulnerability" then why does the linux kernel, 53x the size of Wordpress and a tad more complex than a CMS, not have about 53x more exploits?
Because it's behind a firewall. Do I really need to keep repeating myself?
If I could send remote commands to your kernel, don't you think there would be a few more exploits kicking around?
> Huh? SSH, Postfix and nginx are usually not firewalled.
If you're not restricting access to SSH using a firewall, then you're a bigger idiot than I thought you were.
I'm not sure name calling is really appropriate here. Yes, firewalling stuff is certainly appropriate, particularly administrative things, but key based auth is pretty secure, firewall or no.
You're also nitpicking on a single point when he mentions other things that are definitely not usually firewalled. Your mail and web servers are generally open to the world, regardless of whether or not SSH is.
A CMS is usually used by a company and has different threat scenarios. Usually only sysadmins configure and install extensions.
Source code is not yet published, will be AGPL.
Docker containers: https://github.com/MLstate/PEPS
OwnCloud is licensed under the AGPLv3. Curious why you think it's not Open Source Software.
I'm not being sarcastic, it's fine to say it's broken but that doesn't really make a difference if there are still no better alternatives!?
My impression OwnCloud aims to be a replacement for "the google suite" (not search, but mail, docs, calendar, etc) -- it's really focused at the app layer. I think this is appropriate and there is a need for this.
There's also a need for "a platform which allows users to run arbitrary applications on a server in a secure sandbox", and certainly you can hypothetically build what OwnCloud is aiming at on such a platform. But it's going to take a lot more time and be harder to get right and be reliable and be easy to install and run.
I think OwnCloud is trying to be as easy to install and run as possible, to get a replacement for the google suite wwith apps that work as well as possible and are as easy to use as possible. I think this is a good goal, and they are making reasonable choices toward accomplishing that goal. I am not sure how well they've succeeded.
To install apps into Sandstorm, you literally just click on a link - Sandstorm will manage grabbing the app and installing it for you. Sandstorm itself is a self-contained daemon that can run on any Linux server (and, at some point, there'll be an ISO to install an auto-updating Linux with Sandstorm on it).
https://github.com/MLstate/PEPS
(will be open source AGPLv3, release this month)
wikipedia is in php
facebook is in php
flickr is in php
photobucket is in php
need i say more?
That pretty much makes the point. 194 vulnerabilities in Wordpress with CVEs in 2014.
http://www.cvedetails.com/vulnerability-list/vendor_id-2337/...
Yes, a good developer can write safe code in bad environment. But an average developer writes safer code in a good environment.
Not sure number of disclosed flaws is a good metric to look at, whether it's high or low.
TL;DR simple statistics don't really seem to work well in providing a proper view of comparative levels of security of web apps.
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5203
Facebook is written in PHP, but they have invested a lot into making their PHP not be PHP.