From: John Wilger Date: 2006-08-10T10:07:13+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) On 8/9/06, David Heinemeier Hansson wrote: > The issue is in fact of such a criticality that we're not going to dig > into the specifics. No need to arm would-be assailants. Sorry, but this is ridiculous. Maybe you don't release the exact instructions for how to fix the vulnerability at this time, but without any more details than this, how can any business make an informed decision on whether we really need to spend time upgrading every one of our Rails applications _right now_. Will this vulnerability allow someone to take control of our server and gain network access (high risk for us), or would it just cause our application to crash (low risk for the majority of what we have in the works at the moment)? Does this only affect certain packages or features, or is it a defect in the core of the system? No software is totally secure. Security is about evaluating risk and taking precautions up to a certain point where you start getting diminishing returns. That point is different for every organization and project. Not releasing any more details than this _could_ have a negative effect on the number of applications that get upgraded right away, because we don't have enough information to evaluate what the true risk is. -- Regards, John Wilger http://johnwilger.com ----------- Alice came to a fork in the road. "Which road do I take?" she asked. "Where do you want to go?" responded the Cheshire cat. "I don't know," Alice answered. "Then," said the cat, "it doesn't matter." - Lewis Carrol, Alice in Wonderland