From: Kent Sibilev Date: 2006-08-11T02:13:17+09:00 Subject: Re: [ANN] Rails 1.1.5: Mandatory security patch (and other tidbits) ------=_Part_5974_1303482.1155229986328 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline I completely agree with Kirk. Especially considering that 1.1.5 patch doesn't really fix or opens another security vulnerability. I think rails core team should be more open when it comes to discovered vulnerabilities. An extra pair of eyes wouldn't hurt with the evaluation of the fix. On 8/10/06, khaines@enigo.com wrote: > > On Fri, 11 Aug 2006, Christian Neukirchen wrote: > > > Alternatively, you (or everyone else with a bit experience of Ruby) > > can svn diff yourself. Or, you can search for third-party information > > about the hole, and soon will find something like: > > > > > http://blog.evanweaver.com/articles/2006/08/10/explanation-of-the-rails-security-vulnerability-in-1-1-4-others > > > > There you have a clear explanation which you can prove by looking at > > the code yourself, see if your own application is affected (of course > > it's not, you do the routing thing in a sane way) and have learned > > something for the future. > > I fully agree, and fortunately this is a simple one to go and figure out > for oneself. But my criticism lies more with the general philosophy. It > still opens a potential can of worms (as Evan points out in that blog > entry under Criticism at the bottom of it), and it doesn't actually help > anyone. > > And AFAIK, despite there being information released from 3rd parties, like > that blog entry, about the vulnerability now, there is still no official > statement. > > It's stupid, but when I'm addressing questions from the president of a > company, he puts more credibility behind official explanations from the > source than from random (to his eyes) 3rd party analysis. > > I'll drop it, because what's done is done, and my opinion isn't likely to > change, but I truly hope that future vulnerabilities that are discovered > with any Ruby web framework, or anything else in the Ruby world, will be > handled with greater openness. > > > > Kirk Haines > > > -- Kent --- http://www.datanoise.com ------=_Part_5974_1303482.1155229986328--