security: R-925 — live secrets committed to a world-readable Gitea repo
gates / gates (push) Successful in 5m45s
gates / gates (push) Successful in 5m45s
Found while publishing the legal pages: a background security review flagged
the <!-- source --> comments served in website/adatkezeles.html. Chasing what
those comments point AT found something larger.
MEASURED, and the control is what makes it mean anything:
- manifest_bearer_gate.py itself prints
"manifests/felhom.secret.yaml:39 KNOWN-BACKLOG committed secret"
- that file holds live-shaped values, not placeholders: SECRET_KEY (69),
SUPERUSER_PASSWORD (18), Umami APP_SECRET (66) and POSTGRES_PASSWORD (34),
plus a username/password pair. Values were never printed, only measured
by length.
- gitea.dooplex.hu resolves to 37.191.56.193, the website's public address
- anonymous curl: 200 and 1686 bytes for that file; 200 for hub internals
- OFF-NETWORK CONTROL: fetched from outside the operator's network, a real
path returns the file's first line and a nonsense path returns 404. So
the 200 is genuine anonymous read from the internet, not a LAN-only ACL.
This contradicts documentation/runbooks/secrets.md:3-4, which states secret
values are never committed and the manifests carry only placeholders. That
promise is false today.
Ranked P2, not P1, and the row says why so the operator can overrule: the
exposed credentials guard analytics and an undeployed healthchecks instance,
NOT household data. Measured: umami-db is a ClusterIP service with no
external IP, so the Postgres password is not internet-reachable. No customer
box, hub token or escrow key is in the file.
NOTHING WAS CHANGED. Making the repo private could break the public day-0
installer path (R-110), and rotation plus repo visibility are operator
decisions on production infrastructure. The row carries the order: rotate
first (de-git alone kills nothing — the runbook says so), then decide
visibility, then CC does the de-git and tightens the gate.
Coupled and easy to miss: the 32 source comments on /adatkezeles are harmless
while the repo is public, but become a map of it the moment it is private, so
that is one change and not two. Their traceability is already kept in
documentation/legal/*-1.0.md.
This commit is contained in:
@@ -35,6 +35,27 @@
|
||||
- **Still to prove:** the lost off-site copy alarm (Tester 1's next clean-up
|
||||
window, about 12 October), and the failed-restore hold (needs a scratch off-site store).
|
||||
|
||||
## Needs you soon (2026-10-09): passwords are sitting in a repository anyone on the internet can read
|
||||
|
||||
I found this while publishing the legal pages, not because I went looking — a security check flagged something
|
||||
small in the new page, and following it led here.
|
||||
|
||||
- **What is true:** `gitea.dooplex.hu` answers to anyone, with no login, from anywhere on the internet. I proved
|
||||
that from outside your network, not just from DooPlex. One of the files it hands out is a manifest that
|
||||
contains **real passwords**, not placeholders: the visitor-counter's database password and app key, and the
|
||||
login for the health-check tool. I did not print or copy any of the values.
|
||||
- **How bad:** not as bad as it sounds, and I want to be exact. These guard the **statistics and monitoring
|
||||
bits, not any household's data.** The database itself is not reachable from the internet — I checked. No
|
||||
customer box, no hub key, no backup key is in that file. But they are live passwords, publicly downloadable.
|
||||
- **Your own runbook already says this must not happen** — "secret values are never committed to git" — so the
|
||||
rule is right and the repository is breaking it.
|
||||
- **What to do, in this order:** (1) **change those passwords** — deleting them from the files changes nothing,
|
||||
the history keeps them; (2) decide whether that repository should be readable by strangers at all, bearing in
|
||||
mind the installer people download depends on something public; (3) then I move the values out properly and
|
||||
make the check refuse them in future.
|
||||
- **I changed nothing.** Making the repository private could break the installer that new boxes fetch, and
|
||||
changing passwords on live services is yours to time. It is written up as a register item with the evidence.
|
||||
|
||||
## Legal pages (2026-10-09): the website finally says what it does with people's data
|
||||
|
||||
- **Two new pages are live:** <https://felhom.eu/adatkezeles> (what we do with data) and
|
||||
|
||||
Reference in New Issue
Block a user