From: khaines@... Date: 2006-08-11T01:04:59+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) On Fri, 11 Aug 2006, Christian Neukirchen wrote: > Alternatively, you (or everyone else with a bit experience of Ruby) > can svn diff yourself. Or, you can search for third-party information > about the hole, and soon will find something like: > > http://blog.evanweaver.com/articles/2006/08/10/explanation-of-the-rails-security-vulnerability-in-1-1-4-others > > There you have a clear explanation which you can prove by looking at > the code yourself, see if your own application is affected (of course > it's not, you do the routing thing in a sane way) and have learned > something for the future. I fully agree, and fortunately this is a simple one to go and figure out for oneself. But my criticism lies more with the general philosophy. It still opens a potential can of worms (as Evan points out in that blog entry under Criticism at the bottom of it), and it doesn't actually help anyone. And AFAIK, despite there being information released from 3rd parties, like that blog entry, about the vulnerability now, there is still no official statement. It's stupid, but when I'm addressing questions from the president of a company, he puts more credibility behind official explanations from the source than from random (to his eyes) 3rd party analysis. I'll drop it, because what's done is done, and my opinion isn't likely to change, but I truly hope that future vulnerabilities that are discovered with any Ruby web framework, or anything else in the Ruby world, will be handled with greater openness. Kirk Haines