From: Paul Duncan Date: 2007-01-18T11:05:27+09:00 Subject: Re: Hoe poisoned in Rubyforge --Lg8eXa+brxrbjAbR Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable * SonOfLilit (sonoflilit@gmail.com) wrote: > So if I have a RubyForge account I can upload a modified gem, of, say, > Rails, with a backdoor, and unknowing ruby users will accidentally install > it and open a backdoor in production rails servers? >=20 > This sounds bad. VERY bad. It is very bad. This is the exact problem the package signing in RubyGems was written to address. If only people were using it... > SonOfLilit --=20 Paul Duncan pabs in #ruby-lang (OPN IRC) http://www.pablotron.org/ OpenPGP Key ID: 0x82C29562 --Lg8eXa+brxrbjAbR Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFFrtXkzdlT34LClWIRAs0CAKDV+D+XN1eodKS5sh0+GJa7+nCgLgCgxcnR rHRIMPkKMcYQN0nMKodhvog= =d8HV -----END PGP SIGNATURE----- --Lg8eXa+brxrbjAbR--