From: William Grosso Date: 2006-08-11T01:58:55+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) So, let's pretend for a moment that sometime within the next 24 hours, an "official" explanation of the patch comes out. We'll then have seen the following sequence: 1. Rails team notices issue and fixes issue. 2. Rails team issues patch and announces patch to community. 3. Rails team pauses while patch disseminates through world. Developers who are really concerned about what the patch might contain have complete access to changelogs and sourcecode and can figure out what's being changed. 4. Rails team explains patch withing 48 hours This is *good* performance. Whether or not it's open source or commercial, this is good performance. The pause while the patch was disseminated was probably the right action (certainly, any other course of action would have been more questionable, and put more applications at risk). They've given us an amazing framework, and they're behaving responsibly. I, for one, want to publicly say "Thank you." Bill gwtmp01@mac.com wrote: > > On Aug 10, 2006, at 12:04 PM, khaines@enigo.com wrote: >> And AFAIK, despite there being information released from 3rd parties, >> like that blog entry, about the vulnerability now, there is still no >> official statement. > > Why is it that folks happily use open source software at no cost and then > seem to expect that the accouterments of a legal/business/customer > relationship > must also exist with the authors of the software? > > Or is it the other way around? That the open source folks want all the > *benefits* of a legal/business/customer relationship with their users but > don't want to deal with any associated complaints/risks/liabilities? > > It is probably a little of both. > > Gary Wright > > > > >