bk99.de entertain the web since 1997

Piwik 1.1 closes critical security holes

Summary

In January 2011 the free web analytics software Piwik appeared in version 1.1 with security holes closed. As a precaution, the developers had commissioned Stefan Esser’s company SektionEins with a five-day review of the source code. Its hardening advice was incorporated into the new version.

Ideas

  • A project had its code reviewed before attackers found holes.
  • Besides bugs, an external audit also provides advice on architecture.
  • Five days of review were enough to uncover several holes.

Insights

  • Proactive audits are particularly valuable for self-hosted web applications.
  • Privacy-friendly analytics must also be technically secure.

Facts

  • SektionEins was founded by the security expert Stefan Esser.
  • The review lasted five days.
  • Piwik emerged from the phpMyVisites project and is licensed under the GPL.

References

Critique

  • The report names neither the type nor the severity of the holes found.

Remarks

  • Piwik has been called Matomo since 2018.

Recommendations

  • Always keep self-hosted web analytics such as Matomo up to date.
  • Plan regular external security reviews for your own web applications.

Read the original article

Search the Web Archive