Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As someone that's never worked in rails before, the fact that rails allows you to take parameters from the url, and directly update a database object with them is shocking to me. That's like the first thing you learn about securing websites.


Here's another shocker, cars can be driven off cliffs!! Sue Ford!


As someone who's never driven a Ford (or, indeed, a car), I would not dream of driving one off a cliff, nor would the Github team. It's entirely possible that I would forget to use attr_protected. Github certainly did.


Indeed , seems more akin to buying a second hand car and forgetting to ask if the brakes are actually connected before driving off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: