From: loolek Date: 2008-08-18T18:26:43+09:00 Subject: Re: Security in use of contants "Ok, first, how does the "bad guy", whoever they are, get the ability to "overwrite" it? They shouldn't even be on the same _network_, let alone in my memory space. And, for that matter, if they were in my memory space, they can do a hell of a lot worse than "overwriting a constant". This topic turned to interesting "ruby hacker" lessons. But first let me answare your Qs -> "Ok, first ... whoever they are" a. May be ter*rist or whatever, don' really matter. But they are only one guy. "get the ability to "overwrite" it?" Secound, play that -> i am the bad guy... a. I was won the ruby programmer job at the plant -> I'm in! b. I hacked the box of the security guy of the plant (home machine). Why? Becouse he/she is got connection to the inner plant network (SSH). So i am in again! (idea from Kevin) c. I gave a really cool video game CD to my "new friend Joe", who is working at the plant. Why? Becouse he will install it on the inner box, just for fun. The game will install me among the cool game. So i am in again! d. Maybe in the plant, there is some "hard but alive" way -> between the local and public lan. e. Should i continue? "let alone in my memory space." Hmm, how do you mean this? The ruby code will guard the memory/ hardware/io/etc. I really don't get you? But anyway -> i was first hacked the unpatched Linux kernel... Should i continue the "how"? a. I thought only only the CPU's protected mode can do this kind of job. Or i am wrong? "WE are saying is that you are wrong about how to go about being secure." I think "hypotheticaly" -> i am right. In other words, you STILL don't see the DANGER that the week coding language cousing? "hell of a lot worse than "overwriting a constant"" Oh yes, i see now -> you don't smell the dager still, becouse you asking this silly Q. But okay, what worse could happen? a. You are dead. b. Your home city is dead too. c. You mom is dead too. d. The water in your area is posioned for a long time. e. etc. peter