Now available for pre-order from Amazon.com: Cracking Drupal
webchick: Cracking Drupal is probably going to be the first Drupal book I buy.
The second security advisory for Drupal core in 2009 was just released - SA-CORE-2009-002 Drupal core - Administer content types permission. It is a "public service announcement" reminding site admins that "administer content types" is a very broad permission which, in the hands of a malicious user, includes the ability to take over a site (Edit: on many sites...not all.).
For most sites this doesn't require any action. So, why post the SA at all?
Just Klein Keane and Andrew Rosborough (who work at my fine alma mater) found several issues which they considered vulnerabilities. After discussion with the security team on the issues, they sent reports about the vulnerabilities to various security announcement lists. These get picked up by other folks. Which causes confusion and concern.
People see these and get concerned. How should they fix the problem? What should they do?
So, the security team released a public service announcement to clarify the situation.
Some people have complained (and it's not the first time) that we send too many security announcements. That our releases of core are too often, and that these "public service announcement" posts are pointless. This is a definite concern of the security team, like the little boy children's story if the team "cries wolf" too often then nobody will pay attention to the real announcements.
The security team policies has several related nugets of wisdom related to this topic:
However, public announcements will only be made when the threat has been addressed and a secure version of Drupal is available.
The development branch of Drupal [and contributed modules] is not intended for production use and while security problems are fixed, security announcements are not issued. If you are using the development branch for testing or evaluation, we assume that you will update your code regularly.
It's a tough balance between too many reports and not enough. We're trying and thank you for your patience on this. One potential solution if you feel you are getting too many warnings: use the update feature in core of Drupal 6.x instead of subscribing to the security mailing list. It will only notify you when there is a problem that affects your site.
Comments
On a (un?)related note...
On a (un?)related note, I filed an issue a while back asking to get a link to "drupal.org/security" included in the security announcement emails, but it never got any attention. The current security email template doesn't link to the security announcements page. This seems like an oversight, imo.
Post new comment