3 ms·
How bad is this? I assume they say that Rails-based sessions are secure as they are HMAC'd with a secret, which a timing attack won't break unless the Rails HMA
by Robin_Message 14y ago
How bad is this? I assume they say that Rails-based sessions are secure as they are HMAC'd with a secret, which a timing attack won't break unless the Rails HMAC testing is broken.
- jrochkind1 14y agoIt is confusing. Because of course rack is used by more than just rails, the rack team's responsibility isn't reallyto say "If you're using Rails with it's default signature verification, you're not vulnerable" -- they don't even have the background to be sure that's true (even rails team might not, security is hard). The announcement also implies that the timing vulnerability _might_ only be exposed to people on the same local network who have sufficient timing granularity -- BUT that this applies to anything in the cloud, since people on the same cloud are essentially in same local network. So if you're not in the cloud... On the other hand, I've [fucked up before](http://news.ycombinator.com/item?id=5003132 http://news.ycombinator.com/item?id=5003132) _thinking_ I understood the vulnerability and that it was unlikely to effect me, when in fact I was operating without full information and misunderstanding the true extent of the vulnerability. So now I figure, if the maintainers say "Todays releases are important. All users should upgrade ASAP!", I better just act as if they are right. Even though sometimes they won't be and are being over alarmist, I'm not qualified to know when.