Page MenuHomePhabricator

Make "bin/auth lock" also lock "Customize Messages" in Auth
Open, LowPublic

Description

See D20663. Currently, an attacker who gains control of an administrator account can customize messages in Auth → Customize Messages even if bin/auth lock is locked.

This isn't catastrophic, but the lock should probably cover these messages too, since there are a lot of plausible ways that this attacker can do social-engineering-flavored attacks like replacing the login screen with:

You've won a hog!!! Click [[ http://evil.com/phishing-page.jsp | here ]] and log in to claim your prize!!!!

<... 9000 newlines to hide the rest of the page way below the fold ...>

This isn't quite on the same level as "the NSA secretly invented new prime numbers", but extending the lock generally improves consistency in our approach.