14 ms·
Great news. It's good that all of these bugs have been surfacing lately.
by eric970 14y ago
Great news. It's good that all of these bugs have been surfacing lately.
- instakill 14y agoI don't know why this is being downvoted - I don't think this comment is sardonic. It IS good that they're surfacing because that means we can patch them. Better visible than invisible.
- sandofsky 14y agoIt isn't good. Similar projects with a similar user base, like Django, don't have vulnerabilities of this severity with this frequency. This points to a seriously broken process.
- PetrolMan 14y agoIt isn't a bad thing necessarily. Just because the vulnerabilities haven't popped up in other frameworks doesn't mean they aren't there.
- sandofsky 14y agoThat's creationist logic.
- navyrain 14y agoHardly the same. Lets not kid ourselves into thinking any of the popular software we use is bug-free, which is nigh impossible feat for any large codebase. If this rails bug had not been discovered, it would still be there.
- sandofsky 14y agoWho said software is bug free? The issue is that similar projects, with similar success, with a similar number of developers looking at them, have fewer severe vulnerabilities. The simplest explanation is that one project has more vulnerabilities lying dormant.
- btilly 14y agoNo, it is not. When a particular bit of code gets audited, you tend to find a bunch of holes. And any time you find a conceptual mistake that was made once in code, odds are that a careful audit will find it repeated. Everyone thinks that they are different, until it happens to them.
- techpeace 14y agoNo, it points to a project with a larger user base and much greater degree of scrutiny. No web framework is entirely secure - some have just had more of their insecurities made public.
- eric970 14y ago+1. Agreed.
- FuzzyDunlop 14y agoAre you basing this on how often the vulnerabilities get reported and upvoted on HN? http://www.hnsearch.com/search#request/submissions&q=django+security&start=0 http://www.hnsearch.com/search#request/submissions&q=dja... Django has had its fair share of patches. This is no reflection on the quality of the project, as it shouldn't be for any sufficiently complicated framework (like Rails). I also think the vulnerabilities are similar enough to suggest that the first one gave valid reason to ensure the same issue doesn't occur elsewhere. Rather than dusting these issues under the rug or silently fixing them, they're being responsibly reported with patches and updates provided at the same time. This doesn't seem like broken process to me.
- sandofsky 14y agoNo. I'm basing it on this database: http://www.cvedetails.com/vulnerability-list/vendor_id-12043/product_id-22568/Rubyonrails-Ruby-On-Rails.html http://www.cvedetails.com/vulnerability-list/vendor_id-12043... http://www.cvedetails.com/vulnerability-list/vendor_id-10199/product_id-18211/Djangoproject-Django.html http://www.cvedetails.com/vulnerability-list/vendor_id-10199... Django has 16 vulnerabilities of the DoS, XSS, and CSRF variety. Rails has 37. In addition to DoS, XSS, and CSRF, it has SQL injection and code execution. That we keep seeing similar vulnerabilities suggests the problem is systemic. Giving them praise for not sweeping these under the rug is giving someone praise for not being a sociopath.
- yannski 14y agoSo what does that mean ? That Rails is twice as popular as Django ?
- heimidal 14y agoThe vulnerabilities here only affect versions that have been maintenance-only for almost eighteen months. The last two major versions of Rails (since 3.1, released in August, 2011) are unaffected. In my opinion, the fact that someone bothered to comb through 2.3.x and 3.0.x to find exploits similar to the last one points to a very good process, not a broken one.
- postmodern_mod3 14y ago> Similar projects with a similar user base, like Django, don't have vulnerabilities of this severity with this frequency. Not all Django vulnerabilities have been discovered or reported yet. Just because no one has found or reported a vulnerability, doesn't mean that it it doesn't exist.
- eric970 14y agoI did not mean this sarcastically. It is much better for bugs, especially security bugs, to surface and be dealt with ASAP. Rails is a fantastic framework, but when you have so many dependencies on external libraries, all contributed by different people, things like this are going to happen. I don't think it has anything to do with Rails in particular.