erl-matter

Erlang distribution weaknesses and tooling (by gteissier)

Erl-matter Alternatives

Similar projects and alternatives to erl-matter

  • Zulip

    117 erl-matter VS Zulip

    Zulip server and web application. Open-source team chat that helps teams stay productive and focused.

  • erlang-otp-rce

    Python script to execute commands via Erlang/OTP Distribution Protocol

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better erl-matter alternative or higher similarity.

erl-matter reviews and mentions

Posts with mentions or reviews of erl-matter. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-03-26.
  • Possible Erlang Vulnerability
    2 projects | /r/cybersecurity | 26 Mar 2023
    Here you can find some research about this problem: https://github.com/gteissier/erl-matter
  • Zulip is an open-source team collaboration tool with topic-based threading
    2 projects | news.ycombinator.com | 26 Feb 2022
    > false sense of security

    You don’t think a random generator that looks like it outputs log₂(26²⁰) ≈ 94 bits of entropy, but is limited by the weak PRNG state space to 36 bits, and further limited by poor seeding to about 20 bits, creates a false sense of security?

    (Source: https://github.com/gteissier/erl-matter)

    It would be entirely possible to generate a cookie that gives true security. It would also be possible to generate no cookie at all and force the administrator to become aware of the issue. It would also be possible to limit the exposure to localhost only by default.

    But Erlang does none of these things. It generates a weak cookie that looks like a strong cookie, leaves it in a hidden file that the administrator may never even become aware of, and exposes a daemon that relies on it for security to the internet by default.

    This is not how you build a secure system. This is not even how you build a system to get the administrator to realize that it needs to be secured. This goes against every security best practice that’s been written and some that are so obvious they shouldn’t need to be written. This is irresponsible and inexcusable in today’s environment, and hardly even excusable in the environment that Erlang was originally written for. This needs to be fixed.

Stats

Basic erl-matter repo stats
2
91
0.0
about 1 year ago

gteissier/erl-matter is an open source project licensed under GNU General Public License v3.0 or later which is an OSI approved license.

The primary programming language of erl-matter is Python.

Popular Comparisons


Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com