From: David Masover Date: 2009-07-12T07:44:06+09:00 Subject: Re: [ANN] Ruby Versions site; shell access to historical and current Rubies On Saturday 11 July 2009 03:02:36 pm James Gray wrote: > Yeah, I'm just worried we've gotten into the habit of always over > thinking these security issues. Maybe. Shouldn't be hard to figure it out, though. > So, if you steal my password to David's service, you can do what > exactly? Log into David's service that you were obviously already > logged into? Most people tend to use the same password on multiple services. Those who don't should hopefully be smart enough to use ssh keys instead of passwords for a service like this. > I guess you could run Ruby 1.0 as me instead of you. > Are we worried about that? Well, or take whatever code I'm working on. Or launch attacks on other services, or take keys I've left to other services. > As for "screwing up" the service, well, I'm not too sure what that > means. Make old Ruby interpreters not run correctly? rm -rf / I'm also not sure if this is still an issue, but at one point, it was possible to feed control characters back through an SSH session and at the very least screw up someone's terminal. I wouldn't be surprised if it was possible to actually compromise the connecting machine. Of course, these concerns are already there anyway, but it's generally safer to trust one entity (whoever legitimately has root) than it is to trust many (whoever might access this service).