Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please know that Rails is definitely very secure, and it has gone through many years of testing and review. However, no framework is immune. We should be grateful that the bug was found, patched, and notified, instead of being silently exploited by some black-hat who discovered it first.

The following is speculation, but keep in mind that this bug may have been found because the Rails team has been looking for security holes similar to the exploit that was found a few days ago.



"Please know that Rails is definitely very secure"

It might be secure NOW. But restrospectively, it never was before this patch.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: