4 ms·
Members of our team have been receiving recruiter calls for the past few days - it seems a few places running Rails apps are on the lookout for developers to he
by static_typed 14y ago
Members of our team have been receiving recruiter calls for the past few days - it seems a few places running Rails apps are on the lookout for developers to help secure and update their apps. At least one has apparently experienced the awesomeness of the Ruby way, and had their servers compromised.
Make the decision to move onto Python seem more correct every day.
- heartbreak 14y agoIt is impossible to write insecure web applications in Python. /s
- static_typed 14y agoWe don't seem to see the Python community embrace magic and shiny quite so much as in Ruby. That alone seems to help.
- heartbreak 14y agoThat is subjective. What is "magic and shiny" and who is doing this embracing? "Magic and shiny" is embraced more in Sinatra than in Django? "Magic and shiny" is, by your definition, a security vulnerability?
- rst 14y agoThe Python world has had very, very similar problems. Two popular Django add-ons (piston and tastypie) had remote code execution vulnerabilities due to the exact same cause as the recent Rails RCE vulns: insecure deserialization of YAML. See https://www.djangoproject.com/weblog/2011/nov/ https://www.djangoproject.com/weblog/2011/nov/ This isn't an exactly equivalent situation, since this wasn't a problem with the core Django framework --- but that's in part because the core Django framework does less. Functionality similar to these extensions is bundled with Rails.