news.volyx.in

Stealing secrets from developers using WebSockets (medium.com)

513 points by _gok2 · 2329 days ago · 137 comments on HN

Article summary

The article discusses a security vulnerability where an attacker can steal secrets from developers using WebSockets. The vulnerability allows an attacker to connect to a developer's local WebSocket server and potentially access sensitive information. The exact details of the vulnerability are not available, but the comments suggest it involves exploiting the fact that browsers allow connections to localhost from external sites. This can be mitigated by checking the Host header and Origin header in WebSocket connections.

Main themes

  • WebSocket security vulnerability
  • browser security model
  • domain isolation
  • mitigations and countermeasures
  • developer awareness and education
  • port scanning and network security

What commenters say

  • Developers should check the Host header and Origin header in WebSocket connections to prevent unauthorized access.
  • The vulnerability is not specific to WebSockets, but rather a broader issue with browsers allowing connections to private address spaces.
  • The current security model of domain isolation is outdated and should be replaced with a more robust model, such as an actor model.
  • Mitigations such as checking passwords, using tokens, and validating Origins are not sufficient to prevent attacks, and a more fundamental change to the security model is needed.
  • Some commenters argue that the issue is not a significant threat, as it requires tempting users to visit a malicious site and stay on it while developing JavaScript code.
  • Others argue that the vulnerability is a significant concern, as it can be used to port scan machines on a local network and potentially infer information about Tor circuits.
  • The use of tools like NoScript and uMatrix can help protect against this vulnerability, but may not be foolproof.
  • The vulnerability highlights the need for developers to be aware of the security risks associated with running local servers and to take steps to protect themselves, such as using custom hostnames and validating incoming connections.