donators

n@work Internet Informationssysteme GmbH
Your ad here

Advertising

Security thoughts

By: Thomas

11.07.07 12:56 Age: 1 yrs

Hi,

in the last days a few security bulletins where published. I didn't wrote about them but because we have more reports about such things than in the past I think it's time to think about it. I mean, no software is perfect and we can be lucky that no security hole was found in TYPO3 itself so far. Maybe this is because TYPO3 is save or the people just don't look accurate enough. Anyway, 99% of the security alarms concern third party extensions yet.

The question for me is now, how many bombs sleep inside the TER? I think there are a lot.

The TYPO3 community very big and we have a lot of extensions. Every day new versions and complete new extension are uploaded to the TER. It's impossible for the security team to check them all. Anyway, I guess that only a small part can and should be used due to various reasons currently.

How can we separate the important extensions from the unimportant ones. The extensions that are really used and that which are not used. One possible method is the download counter and I believe that the most popular extension are already reviewed for security.

Another approach could be a general review. A big step forward to get knowledge about the existing extension was the start of the extension comparison team. They check a group of extensions every three months and publish the results in the T3N Magazin. They don't check for security issues but for usability. But that can be used as base information for decreasing the number of potential extension that have to be reviewed by the security team. Or maybe the team-leader should think a corporation. Every time the comparison team checks a group of extensions, they can be also checked for security by the security team.

 

Just my 2 cents,

Thomas

 

Leave a Reply

You have to activate JavaScript to post comments!

Calendar

July 2007
M T W T F S S
« Jun   Aug »
 1
02340506708
09101112131415
16171819202122
23242526272829
3031  

Latest comments

  • paul blondiaux

    Waouuu ! Great, 1000 thanks, THomas. I'm already having great fun trimming the app. ;)...

  • paul blondiaux

    Waouuu ! Great, 1000 thanks, THomas. I'm already having great fun trimming the app. ;)...

  • Thomas

    Hi, lottery closed. Tremendous number of attendees... ;-) Winners should have their licenses in t...

  • Holger Gebhardt

    I was really happy to find this nice tool, over your blog. i used keepassx, but its really uncomfort...

  • Firma

    Could anybody tell me where I can get more about setting Smarty with Eclipse ?

Advertising