[#25936] [Bug:1.9] [rubygems] $LOAD_PATH includes bin directory — Nobuyoshi Nakada <nobu@...>

Hi,

10 messages 2009/10/05

[#25943] Disabling tainting — Tony Arcieri <tony@...>

Would it make sense to have a flag passed to the interpreter on startup that

16 messages 2009/10/05

[#26028] [Bug #2189] Math.atanh(1) & Math.atanh(-1) should not raise an error — Marc-Andre Lafortune <redmine@...>

Bug #2189: Math.atanh(1) & Math.atanh(-1) should not raise an error

14 messages 2009/10/10

[#26222] [Bug #2250] IO::for_fd() objects' finalization dangerously closes underlying fds — Mike Pomraning <redmine@...>

Bug #2250: IO::for_fd() objects' finalization dangerously closes underlying fds

11 messages 2009/10/22

[#26244] [Bug #2258] Kernel#require inside rb_require() inside rb_protect() inside SysV context fails — Suraj Kurapati <redmine@...>

Bug #2258: Kernel#require inside rb_require() inside rb_protect() inside SysV context fails

24 messages 2009/10/22

[#26361] [Feature #2294] [PATCH] ruby_bind_stack() to embed Ruby in coroutine — Suraj Kurapati <redmine@...>

Feature #2294: [PATCH] ruby_bind_stack() to embed Ruby in coroutine

42 messages 2009/10/27

[#26371] [Bug #2295] segmentation faults — tomer doron <redmine@...>

Bug #2295: segmentation faults

16 messages 2009/10/27

[ruby-core:25981] Re: Disabling tainting

From: Tony Arcieri <tony@...>
Date: 2009-10-07 03:11:57 UTC
List: ruby-core #25981
On Tue, Oct 6, 2009 at 3:52 AM, Yugui <yugui@yugui.jp> wrote:

> Why do you think the feature is not useful?
>

To really build a secure system around something like $SAFE/taint, you must
be extremely vigilant with handling the flow of tainted objects through the
system.  One little mistake anywhere and it doesn't offer you any security
at all.


> It might not be useful for you but some ruby programs developed on
> early era often use it.
>

That's fine, but 99.9% of Ruby programs out there don't use it and it
impacts performance, so isn't making it an on-by-default configurable option
a good idea?


> And Ruby 1.9 has even trust/untrusted model in addition to
> taint/untainted for more secure/usable security checking.
>

The need for something like trust/untrusted shows is that $SAFE/taint are no
where good enough.

-- 
Tony Arcieri
Medioh/Nagravision

In This Thread