From: Patrick Hurley Date: 2006-06-16T22:18:20+09:00 Subject: Re: ZenObfuscate - for when you really really have to ship a On 6/16/06, Austin Ziegler wrote: > That's not the point of ZenObfuscate. It doesn't turn Ruby into a > "static" language. If you want to prevent code injection, you need to > defend against it in your application. I believe that the injection he is talking about after the application is deployed with rails still in plain text view, having someone open the rails files and add code that could over write methods, etc. Of course this implies a pretty sophisticated understanding of Ruby and the application. And also leads to a pretty difficult chain -- now you have to handle all the standard libraries that are used as well, otherwise the same user could inject their code there as well. Don't forget about the RUBYOPT environment variable or even modifying the ruby interpreter. I am not against any of these things and may likely purchase ZenObfuscate for our company at some point, but to base any business model around the purity of code (in any language, but especially dynamic languages) run on a clients machine is a mistake. You can take some baby steps to hide stuff, but the cost/benefit ratio slips rapidly when you try to defend against a reasonably sophisticated attacker. pth