From: James Britt Date: 2006-08-10T04:06:15+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) khaines@enigo.com wrote: > > This seems misguided to me. One of the things that I have always > appreaciated about the general open source environment is that when > there is a security vulnerability it is announced. It is described. And > it is fixed. > > The process is open, and it works because someone can go and look at the > information about the vulnerability and learn from it, and they can have > faith in the advice to upgrade because the vulnerability announcement is > clear about what the exploit is and the risk from it. I agree. I understand there's value in insisting on applying the upgrade rather than going into detail; people may decide that they can simply patch the code themselves, or misunderstand the security risk and put off the upgrade. But that should be the individual's call. Besides, if one does a diff from 1.1.4 and 1.1.5, wouldn't the problem be exposed anyway? Security through obscurity is not going to be a big hindrance to people intent on doing bad things. The cat's out of the bag. -- James Britt "In Ruby, no one cares who your parents were, all they care about is if you know what you are talking about." - Logan Capaldo