32 karma · joined March 19, 2021
I remember two meters of snow, digging tunnels through it and such.
And I remember four distinct seasons. Now it's more like a long summer, a long autumn, and short spring and winter.
Of course, but that's a weakness that concerns the user, not the platform.
It is not a flaw of Facebook's security model.
So, after Edward is discovered, all sessions are remotely logged off and all accounts created during that hour are blocked, asked to confirm their email, phone or even identity, or deleted.
So, after one hour, Edward is left with nothing more than braggable rights. And personal data of billions, but not their passwords.
I don't think the reproducibility is out. It's the same app, the same image, the same intended user, you just inject, once, the local user and group ids.
See more here: https://stackoverflow.com/a/50900530/15428104
$ declare -p UID declare -ir UID="1000"
The -x option is missing.
In fact, docker-compose up -d takes care of the build thing by itself. It's a five second tradeoff for the lifetime of the application.
You run docker-compose build ONCE and you're set. On my machine, it takes five seconds.
Heck, you can even run docker-compose build everytime you start the application, it will use the cached build and take less than one second.
---
Correction: the docker-compose up -d takes care of the build process the first time it runs.
Literally, it takes more to complain about the issue than build the image ONCE.
You set it to the output of id -u and id -g. It's two lines. There are definitely lots of things more complex when dealing with docker than this.
You provide the team with a script containing those two lines and a docker-compose wrapper and you're set.
Of course it would have been better not to have to care about these things, but hey, at least you're not installing and configuring 4-5 services to bootstrap an application.
The only tedious thing is you have to adapt this for every image type you run.
Make the build script use local $USERID and $GROUPID as args during the build process.
In docker-compose.yml (or, if using docker directly, using --build-arg):
build:
context: ./build
args:
USERID: ${USERID}
GROUPID: ${GROUPID}
So you're passing the local uid and gid as variables to the build process.(1)In build/Dockerfile:
FROM image:tag
WORKDIR "/application"
ARG USERID
ARG GROUPID
RUN if [ ${USERID:-0} -ne 0 ] && [ ${GROUPID:-0} -ne 0 ]; then userdel -f www-data ;fi \
&& if getent group ${GROUPID} ; then groupdel www-data; fi \
&& groupadd -g ${GROUPID} www-data && useradd -m -l -u ${USERID} -g www-data www-data -s /bin/bash \
(1) $USERID and $USERID might not be available as an environment variable on your system. To do so, place this under .bashrc: export USERID=$(id -u)
export GROUPID=$(id -g)