3 ms·
People are coming to the realization that Ruby is a fundamentally insecure language. I've given my reasoning for this, though with respect to a discussion on st
by ryandv 1y ago
People are coming to the realization that Ruby is a fundamentally insecure language. I've given my reasoning for this, though with respect to a discussion on static analysis, here [0]. Ruby, Rails, the library ecosystem, and the entire language, are actually one giant monolith, in that any one package, or really anybody with access to the runtime, can modify and monkey patch any other package. This is not a glaring security flaw at all, but rather a result of how "awesome" Ruby is in letting you make "Extensions to All Objects," [1] including core data types such as String, Array, Hash, and Integer.
Point the second: People are feeling emboldened to bypass rule of law and take matters into their own hands, up to and including taking other peoples' lives. Not only is this time fraught with political tension, it is also approaching the most crucial time of the year for ecommerce and online retailers - the holiday shopping season.
Put two and two together and it's not hard to see why people are scrambling to secure the software supply chain.
[0] https://news.ycombinator.com/item?id=45104910 https://news.ycombinator.com/item?id=45104910
[1] https://guides.rubyonrails.org/active_support_core_extensions.html#extensions-to-all-objects https://guides.rubyonrails.org/active_support_core_extension...