It’s never a great sign when I spend my entire workday listening to Radiohead. We’re not scaremongering, this is really happening.
There was an absolutely massive Rails security vulnerability disclosed today. This is legitimately probably the worst one I have seen since 2012, when GitHub itself was exploited. (And yep, GitHub is itself a Rails app.)
And guess which top-tier research university library runs six Rails apps in production! That’s right, it’s Berkeley. So, I spent literally my entire shift fixing everything up. It looks like we are in the clear now. All comfy, all updated, all secure.
If there was one thing I wish “normal” people understood – the random general public at large, not any one group or anything – it’s that every day there isn’t a huge, life-altering security breach, it is because of the blood sweat and tears of people like me. We watch for new vulnerabilities, and we act immediately. And we try to think of ways to mitigate the “attack surface”, too, so that if a vulnerability is missed, it won’t do as much damage or compromise as much data.
Information security is a big thing. People seem to think it is just sitting around at a computer and eating food all day, or telling an AI to go write some code. It’s a massive undertaking. The same way I am thankful to the construction workers who make the roads and bridges I use every day, I am thankful to the security workers who make sure my data doesn’t leak everywhere.
I should also note that Monday, there was a spear phishing campaign against us as well. We received very well-crafted emails using official looking logos and text that wanted us to “reactivate our accounts”, which of course is a scam. I reported this not just to our Berkeley security office, but also the security office of the organisation where the emails originated. That organisation reached out to me yesterday and said they were able to find the source of the hack and take care of it! Yay! That is one less way for a hacker to get into systems.
It’s just also so exhausting, haha. I wish there was a day where I didn’t have to be on edge, waiting for the next security incident to drop. It’s the closest I’ve felt to “burn out” since I worked in startups. I just want to work on building projects that help people. Not going around chasing after hackers and trying to keep them out of where they don’t belong.
And I know, that itself is helping people. It’s what keeps me going on stuff like this. But days like today are just super tiring. Almost eight hours of nothing in my head but “secure the systems! patch the thingies! update the tickets! MORE BUILDS!”