Hacker News new | past | comments | ask | show | jobs | submit login

I wonder how new devs feel about learning Rails now that yaml has been discovered to be a serious attack vector, and will possibly (probably) be a source of many security concerns in the future.



I feel much better now. Rails enjoyed that near invincible status long enough and the other shoe was bound to drop sooner rather than later. Now that we've got this out of the way, as well as the mass assignment issue of last year, maintainers will hopefully take POCs and disclosures more seriously in the future.


Depends on whether or not they understand what it does.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: