r/PHP • • 10h ago

Is anyone here using Drupal Steward?

/r/drupal/comments/1wyndv3/is_anyone_here_using_drupal_steward/
0 Upvotes

6 comments sorted by

2

u/qoneus 9h ago

I have experience with Drupal Steward in both of its forms. I think the thing to set your expectations on (which they are very clear about) is that this is a set of WAF rules and advance disclosures. So think about the class of threat WAF rules can protect against: it's not everything. But it's enough that gives you the time to patch with some amount of peace of mind in the event of a 0-day.

1

u/tekNorah 8h ago

That's fair. Has Steward met your expectations in practice?

I'm also curious what else you're doing alongside it to reduce the attack surface.

Do you find that Steward is mostly a backstop for that patch window, with other measures doing more of the day-to-day work?

1

u/qoneus 8h ago

Has Steward met your expectations in practice?

Yes, it's met our expectations. Part of the Drupal Security process involves making sure Drupal Steward is configured correctly and the disclosures are made to the right companies before disclosing the CVE to the public, and it's had a 100% success rate as far as I know.

I'm also curious what else you're doing alongside it to reduce the attack surface.

In this particular area, constant software updates, and gating deployment on updated software, tracked by things like Orca Shift Left, Kyverno policies, Snyk, etc. has proven to be the biggest thing to move the needle.

Do you find that Steward is mostly a backstop for that patch window

It's 100% just a backstop for the disclosure to patch deployment window. You still need to keep track of updates and apply them. Purely for COGS, I would assume they're removing older WAF rules as time goes on.

1

u/rustprogram 8h ago

lmao like ten years ago when I worked on a team that also supported a drupal website, a senior developer literally patched drupal core and nobody batted an eye. I am sure it was not the only place where she did it either...

1

u/umulmrum 3h ago

I don't use Drupal but this offer rings a huge bell. With the standard plan you route your complete traffic to them, and as they terminate TLS and re-encrypt traffic to your servers, they can both read and manipulate data. I'd see this as a security issue that is more critical than most vulnerabilities. You need to trust both in their good will and their technical expertise to make that thing secure (this is also a honey pot that will attract attackers). And what happens if you combine this with CloudFlare for DDoS protection?

The on-premise alternative should be better in that regard, but no public price means that's likely expensive. Not sure what "advance notice of every public advisory" means exactly. Do they share vulnerabilities before they get public? Does an attacker just need to register to have extra time to prepare attacks?

1

u/Eiltott 3h ago

I don't know if I'm using it wrong but I've inherited a Drupal project at work and it is so strange and never works as I expect