Issue 047 — and the half that runs the other way #42
@@ -51,6 +51,33 @@ firewall that is up and dropping by default.
|
|||||||
That is the worst shape a security fault can take: the mechanism is present, it reports success, and
|
That is the worst shape a security fault can take: the mechanism is present, it reports success, and
|
||||||
the thing it is believed to be doing is not the thing it does.
|
the thing it is believed to be doing is not the thing it does.
|
||||||
|
|
||||||
|
## The other half, which runs the opposite way
|
||||||
|
|
||||||
|
The section above is about ports the firewall **cannot close**. There is a matching fault about
|
||||||
|
ports it **does** close and should not, and together they are worse than either alone.
|
||||||
|
|
||||||
|
The rules are computed from what modules declare they listen on. During a migration a mesh knows
|
||||||
|
about almost nothing — the services are still running under the system being replaced — so it opens
|
||||||
|
almost nothing. Anything listening **on the host** rather than in a container is then dropped.
|
||||||
|
|
||||||
|
**Including ssh.** No module in the catalogue declares an ssh port, and the generator has no
|
||||||
|
built-in allowance for one. So the ruleset loaded on a machine that has not been told otherwise
|
||||||
|
accepts established connections, loopback and ping, and refuses every new ssh connection.
|
||||||
|
|
||||||
|
The session doing the loading survives, because established connections are accepted. It survives
|
||||||
|
until it drops. On a machine reached over the network that is the difference between a mistake and
|
||||||
|
a journey to a rescue console.
|
||||||
|
|
||||||
|
So the two halves are:
|
||||||
|
|
||||||
|
| | what it does | consequence |
|
||||||
|
|---|---|---|
|
||||||
|
| container ports, published | cannot see them, does not filter | stay open, protection silently lost |
|
||||||
|
| host ports, undeclared | sees them, drops them | **ssh among them** |
|
||||||
|
|
||||||
|
The mesh gets no say over the ports most worth protecting, and full say over the one that must never
|
||||||
|
be closed by accident.
|
||||||
|
|
||||||
## How it would be checked
|
## How it would be checked
|
||||||
|
|
||||||
Two probes from another machine, against a port on the host and a published container port, before
|
Two probes from another machine, against a port on the host and a published container port, before
|
||||||
|
|||||||
Reference in New Issue
Block a user