r/PHP • u/tekNorah • 10h ago
Is anyone here using Drupal Steward?
/r/drupal/comments/1wyndv3/is_anyone_here_using_drupal_steward/1
u/rustprogram 8h ago
lmao like ten years ago when I worked on a team that also supported a drupal website, a senior developer literally patched drupal core and nobody batted an eye. I am sure it was not the only place where she did it either...
1
u/umulmrum 3h ago
I don't use Drupal but this offer rings a huge bell. With the standard plan you route your complete traffic to them, and as they terminate TLS and re-encrypt traffic to your servers, they can both read and manipulate data. I'd see this as a security issue that is more critical than most vulnerabilities. You need to trust both in their good will and their technical expertise to make that thing secure (this is also a honey pot that will attract attackers). And what happens if you combine this with CloudFlare for DDoS protection?
The on-premise alternative should be better in that regard, but no public price means that's likely expensive. Not sure what "advance notice of every public advisory" means exactly. Do they share vulnerabilities before they get public? Does an attacker just need to register to have extra time to prepare attacks?
2
u/qoneus 9h ago
I have experience with Drupal Steward in both of its forms. I think the thing to set your expectations on (which they are very clear about) is that this is a set of WAF rules and advance disclosures. So think about the class of threat WAF rules can protect against: it's not everything. But it's enough that gives you the time to patch with some amount of peace of mind in the event of a 0-day.