PowerShell / PowerShell/PSScriptAnalyzer

PSAvoidUsingConvertToSecureStringWithPlainText shouldn't always be flagged by PSGallery.

オープン
#562 コメント 3 件 リアクション 1 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

Issue - Discussion
主要言語
C#
スター
2.2k
フォーク
414
平均マージ
13時間 1分
マージ済み PR(30日)
2

説明

I have a module that I just Published that was flagged by the PSGallery. The issue encountered is PSAvoidUsingConvertToSecureStringWithPlainText. While I understand why this rule is in place, and I have [SecureString] parameters in this module where it makes sense, but blanketing it over everything is problematic and can actually hurt security rather than improve it.

My module encrypts the user's AccessToken/ApiKey using PBDKF2 with a Password and Salt and stores it in an AppData folder. The AccessToken is a [string] supplied by the user. It is being encrypted in a file for later use, and then is loaded into a new session via a command to decrypt the key and do a few other things before the other commands in the module can be used. Below is the portion that got flagged.


        $SecureKeyString = ConvertTo-SecureString -String $AccessToken -AsPlainText -Force

        # Generate a random secure Salt
        $SaltBytes = New-Object byte[] 32
        $RNG = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
        $RNG.GetBytes($SaltBytes)

        $Credentials = New-Object System.Management.Automation.PSCredential -ArgumentList 'user', $MasterPassword

        # Derive Key, IV and Salt from Key
        $Rfc2898Deriver = New-Object System.Security.Cryptography.Rfc2898DeriveBytes -ArgumentList $Credentials.GetNetworkCredential().Password, $SaltBytes, 10000
        $KeyBytes  = $Rfc2898Deriver.GetBytes(32)

        $EncryptedString = $SecureKeyString | ConvertFrom-SecureString -key $KeyBytes

        $ConfigName = 'api.key'
        $saltname   = 'salt.rnd'

        if (!(Test-Path -Path "$($ConfigPath)"))
        {
            New-Item -ItemType directory -Path "$($ConfigPath)" | Out-Null
        }

        Write-Verbose -Message "Saving the information to configuration file $("$($ConfigPath)\$ConfigName")"

        "$($EncryptedString)"  | Set-Content  "$($ConfigPath)\$ConfigName" -Force

        # Saving salt in to the file.
        Set-Content -Value $SaltBytes -Encoding Byte -Path "$($ConfigPath)\$saltname" -Force

In this circumstance, what added benefit does requiring a SecureString give when the value needs to be available as a string when used via the API this module is invoking. It being used via ConvertTo-SecureString as plain text doesn't really change anything since it already needs to be used as plaintext. What it is trying to protect is when the key is stored in a file.

I think this is an area you have to be careful. If you push too hard and flag things like this, people will just avoid attempting to secure something and just say stick it in plaintext somewhere.

You can see in the below example, where if I just avoided encryption altogether, I likely wouldn't have been flagged.

Publish-Module [-FormatVersion [<Version>]] [-IconUri [<Uri>]] [-LicenseUri [<Uri>]]
    [-NuGetApiKey [<String>]] [-ProjectUri [<Uri>]] [-ReleaseNotes [<String[]>]] [-Repository
    [<String>]] [-RequiredVersion [<Version>]] [-Tags [<String[]>]] -Name <String> [-Confirm]
    [-WhatIf] [<CommonParameters>]

I just wanted to point this out [-NuGetApiKey []]

I wanted to get a little clarification on this, and maybe see where I can get a list of Tests that are ran via PSGallery so I can run them during my Tests before I reach this point. This code came from Carlos Perez who said I could adapt it to my module. He has multiple modules with this exact usage in the PSGallery and never had issue or has had them flagged.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず PSAvoidUsingConvertToSecureStringWithPlainText の実装と既存のテストを見つけ、次に PSGallery がアナライザーをどのように呼び出しているかを比較します。安全でない平文変換と意図的な平文変換を再現可能な形で区別する基準を定義し、テストカバレッジを追加します。報告されたケースが処理され、真に安全でない findings が弱められていなければ完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
powershell
領域
security, tooling
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。