From: SonOfLilit Date: 2007-01-15T01:12:22+09:00 Subject: Re: Hoe poisoned in Rubyforge ------=_Part_56950_26274061.1168791139132 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline I too think so, but probably most people don't work with a local audited gem server, and just install gems from rubyforge - so the rubyforge people carry this responsibility, whether they want it or not. They are not /obligated/ to act accordingly, but it would be appropriate that they do. IMHO. On 1/14/07, Gregory Brown wrote: > > On 1/14/07, SonOfLilit wrote: > > So if I have a RubyForge account I can upload a modified gem, of, say, > > Rails, with a backdoor, and unknowing ruby users will accidentally > install > > it and open a backdoor in production rails servers? > > I think if security is an issue, you should not download directly from > RubyForge via gems, but set up an audited gem server locally. (Or > download the files and gem install them locally) > > Of course, this does not mean that such a problem isn't seriously > disruptive. > > ------=_Part_56950_26274061.1168791139132--