Urgent.News

What's breaking now, across thousands of outlets.

Tech

I Said Isolation Was Structural. Then Tenancy Shipped and Proved Me Right the Hard Way

In the last piece of my v0.1.0 series I wrote a sentence I was proud of and not yet entitled to: "isolation is structural or it's imaginary." I deferred it. Single-tenant was the honest scope for a first release. v0.2.0 shipped multi-tenancy on HivePlane . Then I ran an adversarial suite against my own boundary, and the sentence stopped being a thesis and became a bug list. Seven findings in the…

In the latest installment of the v0.1.0 series, a statement was made that isolation is structural or it is imaginary. This assertion was later proven to be accurate through rigorous testing. The first multi-tenancy release, v0.2.0, was shipped for HivePlane. Subsequently, an adversarial suite was run against the system, revealing seven findings, or nine if the combined findings are considered. These findings confirmed that the system was inferring tenancy rather than asserting it.

Each instance of inferred tenancy was due to a place where the system incorrectly used a client-supplied value as an identity, rather than enforcing isolation at the storage primary key and the authenticated principal. The vulnerabilities included a worker hijack, where a workload registered under one tenant could be accessed by another tenant using a worker ID alone.

Another issue involved a spoofable header used for rate limiting, which could be manipulated by an attacker to consume another tenant's resources. Additionally, approvals, security events, and incident states were found to default to a default tenant, allowing cross-tenant access to sensitive information.

The source also highlights that default tenants are not a safe default and can lead to silent cross-tenant leaks. To address these issues, composite primary keys should be used, TenantScopeError should be raised on cross-tenant writes, and adversarial field tests should be conducted to attack each boundary instead of testing only happy paths. The article emphasizes that inference is not enforcement and that composite primary keys, proper error handling, and rigorous testing are the keys to ensuring true tenancy isolation.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Break It, Then Ask Why: Exposing a Hidden Internal Dev Console With One Flipped Flag

Honestly, this one was kind of an accident. I'd been on this travel site for a couple of hours (the big booking one) and had basically nothing to show for it.

  • Hidden internal developer console exposed on travel booking website
  • Boolean flags set to true revealed console due to validation flags set to false
  • Console contained internal service names, ports, and override options

Reimplementing a Trie Reminded Me How Autocomplete Actually Works

I spent an embarrassing amount of time last week reimplementing something I'd "known" since a data structures class a decade ago: the trie.

  • Trie stores strings by character along shared paths from root
  • Autocomplete features utilize trie's prefix lookup mechanism
  • Trade-off of naive trie implementation is significant memory waste

More from Friday 2 October →