From: Tom Copeland Date: 2007-01-18T11:16:02+09:00 Subject: Re: Hoe poisoned in Rubyforge On Thu, 2007-01-18 at 11:05 +0900, Paul Duncan wrote: > * SonOfLilit (sonoflilit@gmail.com) wrote: > > So if I have a RubyForge account I can upload a modified gem, of, say, > > Rails, with a backdoor, and unknowing ruby users will accidentally install > > it and open a backdoor in production rails servers? > > > > This sounds bad. VERY bad. > > It is very bad. Well, maybe "was", since the problem "SonOfLilit" was talking about has been fixed. > This is the exact problem the package signing in > RubyGems was written to address. > > If only people were using it... Something like that would be good, and I encourage folks to read through Paul's posts to rubygems-developers to get an idea of the possibilities of gem signing. Yours, Tom