zlacker

[parent] [thread] 6 comments
1. dfsego+(OP)[view] [source] 2025-01-05 14:31:28
I feel this. Recently implemented a very trivial “otp to sign an electronic document” function in our app.

Security heard “otp” and forced us through a 2 month security/architecture review process for this sign-off feature that we built with COTs libraries in a single sprint.

replies(2): >>malfis+y7 >>smarx0+Q7
2. malfis+y7[view] [source] 2025-01-05 15:31:54
>>dfsego+(OP)
Oh I know that feeling. We got in hot water because the codes were 6 digits long and security decided we needed to make them eight digits.

We pushed back and initially they agreed with us and gave us an exception, but about a year later some compliance audit told them it was no longer acceptable and we had to change it ASAP. About a year after that they told us it needed to be ten characters alphanumeric and we did a find and replace in the code base for "verification code" and "otp" and called them verification strings, and security went away.

replies(1): >>dfsego+at4
3. smarx0+Q7[view] [source] 2025-01-05 15:34:41
>>dfsego+(OP)
To be fair, I would also be alarmed, albeit not by OTP. "sign an electronic document" and "built with COTs libraries in a single sprint" is essentially begging for a security review. Signatures and their verification are non-trivial, case in point: >>42590307
replies(1): >>talkin+pl
◧◩
4. talkin+pl[view] [source] [discussion] 2025-01-05 17:23:39
>>smarx0+Q7
Nobody said you shouldn’t do any due diligence. But 1 sprint vs 2 months of review really smells like ‘processes over people’. ;)
replies(1): >>normie+my
◧◩◪
5. normie+my[view] [source] [discussion] 2025-01-05 19:03:15
>>talkin+pl
A more positive view would be that the security team may have had different priorities to the product team.
replies(1): >>robert+D61
◧◩◪◨
6. robert+D61[view] [source] [discussion] 2025-01-06 00:11:25
>>normie+my
Two months of review after the work would be a lot more useful than before.
◧◩
7. dfsego+at4[view] [source] [discussion] 2025-01-07 04:14:35
>>malfis+y7
Heh. We also got treated to the digit thing. That topic alone was about 30 mins of mtg. time with a vp of eng and 2 seniors in the mtg.
[go to top]