GitHub incidents spawns Rails security debate
GitHub incidents spawns Rails security debate
Posted Mar 8, 2012 21:47 UTC (Thu) by bronson (subscriber, #4806)In reply to: GitHub incidents spawns Rails security debate by cate
Parent article: GitHub incidents spawns Rails security debate
The value in what Homakov did was demonstrating that even extremely competent, experienced Rails developers don't always follow the docs. I'm not sure how anyone could do that without actually showing it in the wild.
GitHub incidents spawns Rails security debate
Posted Mar 15, 2012 15:07 UTC (Thu)
by rqosa (subscriber, #24136)
[Link] (1 responses)
Posted Mar 15, 2012 15:07 UTC (Thu) by rqosa (subscriber, #24136) [Link] (1 responses)
> This bug would never merit a CVE.
Do you mean the Rails default behavior, or the GitHub vulnerability? It seems like the GitHub vulnerability would have merited a CVE — if it weren't for the GitHub software being purely in-house (not distributed outside of GitHub, Inc.), correct?
GitHub incidents spawns Rails security debate
Posted Mar 26, 2012 20:29 UTC (Mon)
by bronson (subscriber, #4806)
[Link]
Posted Mar 26, 2012 20:29 UTC (Mon) by bronson (subscriber, #4806) [Link]
But, while I've done a fair amount of Rails, I'm not the most in touch with CVEs.