Empty config lists should trigger errors, not grant unlimited access
A widespread security flaw in software configuration allows empty or missing access lists to silently default to full, unrestricted permissions rather than denying access. This pattern, dubbed 'privilege by omission,' can arise from routine actions like refactoring, accidental line deletions, or simple typos that cause carefully written rules to be ignored. Unlike an explicit 'allow all' marker that is visible during code review, these silent defaults leave no obvious trace that maximum privilege has been granted. Developers argue that systems should instead reject empty grants with a loud error at load time, forcing the issue to be noticed and fixed immediately. The recommended fix requires that unrestricted access be declared explicitly, such as with a wildcard marker, and that any grant naming no capabilities at all be treated as a configuration error.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in