Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, Egor's hack accomplished two things:

(1) it has seemingly embarrassed some rails committers into taking this seriously, whereas they dismissed the issue before;

(2) I bet there were at least 20 devs who saw this on HN, said fuck my life, and hopped on their vpn to check if their site is vulnerable.

No drama disclosures didn't accomplish either of these things. Hopefully github won't take it too personally, and Egor was actually (as he seemed!) careful not to break anything.



20? He listed four or five way popular websites alone. Egor is my hero for this week, so thankful for his wake-up call to the Rails world.


(And I am not being a hater here, I am also using Rails for some hobby projects & had to double check all my code. I somehow didn't even think about foreign keys in mass assignment... sigh.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: