PowerShell / PowerShell/PSScriptAnalyzer

PSAvoidUsingConvertToSecureStringWithPlainText shouldn't always be flagged by PSGallery.

Đang mở
#562 3 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Issue - Discussion
Ngôn ngữ chính
C#
Star
2.2k
Fork
414
Merge trung bình
13 giờ 1 phút
Pull request đã merge (30 ngày)
2

Mô tả

I have a module that I just Published that was flagged by the PSGallery. The issue encountered is PSAvoidUsingConvertToSecureStringWithPlainText. While I understand why this rule is in place, and I have [SecureString] parameters in this module where it makes sense, but blanketing it over everything is problematic and can actually hurt security rather than improve it.

My module encrypts the user's AccessToken/ApiKey using PBDKF2 with a Password and Salt and stores it in an AppData folder. The AccessToken is a [string] supplied by the user. It is being encrypted in a file for later use, and then is loaded into a new session via a command to decrypt the key and do a few other things before the other commands in the module can be used. Below is the portion that got flagged.


        $SecureKeyString = ConvertTo-SecureString -String $AccessToken -AsPlainText -Force

        # Generate a random secure Salt
        $SaltBytes = New-Object byte[] 32
        $RNG = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
        $RNG.GetBytes($SaltBytes)

        $Credentials = New-Object System.Management.Automation.PSCredential -ArgumentList 'user', $MasterPassword

        # Derive Key, IV and Salt from Key
        $Rfc2898Deriver = New-Object System.Security.Cryptography.Rfc2898DeriveBytes -ArgumentList $Credentials.GetNetworkCredential().Password, $SaltBytes, 10000
        $KeyBytes  = $Rfc2898Deriver.GetBytes(32)

        $EncryptedString = $SecureKeyString | ConvertFrom-SecureString -key $KeyBytes

        $ConfigName = 'api.key'
        $saltname   = 'salt.rnd'

        if (!(Test-Path -Path "$($ConfigPath)"))
        {
            New-Item -ItemType directory -Path "$($ConfigPath)" | Out-Null
        }

        Write-Verbose -Message "Saving the information to configuration file $("$($ConfigPath)\$ConfigName")"

        "$($EncryptedString)"  | Set-Content  "$($ConfigPath)\$ConfigName" -Force

        # Saving salt in to the file.
        Set-Content -Value $SaltBytes -Encoding Byte -Path "$($ConfigPath)\$saltname" -Force

In this circumstance, what added benefit does requiring a SecureString give when the value needs to be available as a string when used via the API this module is invoking. It being used via ConvertTo-SecureString as plain text doesn't really change anything since it already needs to be used as plaintext. What it is trying to protect is when the key is stored in a file.

I think this is an area you have to be careful. If you push too hard and flag things like this, people will just avoid attempting to secure something and just say stick it in plaintext somewhere.

You can see in the below example, where if I just avoided encryption altogether, I likely wouldn't have been flagged.

Publish-Module [-FormatVersion [<Version>]] [-IconUri [<Uri>]] [-LicenseUri [<Uri>]]
    [-NuGetApiKey [<String>]] [-ProjectUri [<Uri>]] [-ReleaseNotes [<String[]>]] [-Repository
    [<String>]] [-RequiredVersion [<Version>]] [-Tags [<String[]>]] -Name <String> [-Confirm]
    [-WhatIf] [<CommonParameters>]

I just wanted to point this out [-NuGetApiKey []]

I wanted to get a little clarification on this, and maybe see where I can get a list of Tests that are ran via PSGallery so I can run them during my Tests before I reach this point. This code came from Carlos Perez who said I could adapt it to my module. He has multiple modules with this exact usage in the PSGallery and never had issue or has had them flagged.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu bằng cách xác định phần triển khai và các bài kiểm thử hiện có cho PSAvoidUsingConvertToSecureStringWithPlainText, sau đó so sánh cách PSGallery gọi analyzer. Xác định một cách phân biệt có thể tái lập giữa việc chuyển đổi plaintext không an toàn và việc chuyển đổi plaintext có chủ đích, đồng thời bổ sung coverage; được xem là hoàn tất khi trường hợp được báo cáo được xử lý mà không làm suy yếu các finding thực sự không an toàn.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
powershell
Lĩnh vực
security, tooling
Loại issue
Lỗi
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.