From: James Britt Date: 2006-08-10T04:51:16+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) Matthew Smillie wrote: > In other words, if you lose your entire database two hours after the > announcement (because it was announced at 2am local time, say), it's > pretty cold comfort that the vulnerability was openly discussed and > evaluated according to all the best practices of the open-source > community. Good point. I think what may have been irksome is the perception of the initial post as saying, "I'm not telling you the details; trust me, it's for your own good." Which may be essentially true, but at some point (and it will happen one way or the other) a discussion of the details is needed. > > In any case, the only thing missing is a spoon-fed description of the > vulnerability. The fix itself is public, and if you're into that sort > of thing, I'm sure you could get a good idea of the exploit by > examining changes to the source code. It's not on /. yet? Or warezonrailz.ru? :) -- James Britt http://www.ruby-doc.org - Ruby Help & Documentation http://www.artima.com/rubycs/ - The Journal By & For Rubyists http://www.rubystuff.com - The Ruby Store for Ruby Stuff http://www.jamesbritt.com - Playing with Better Toys