This post originated from an RSS feed registered with Ruby Buzz
by rodney ramdas.
Original Post: Security through Obscurity ? Not !
Feed Title: pinupgeek.com
Feed URL: http://feeds.feedburner.com/pinupgeek
Feed Description: A personal take on Ruby and Rails
A lot of people are getting all hot in the face about the alleged ‘security through obscurity’ policy of Rails Core with regards to problems found in version 1.1.4 and before (note the update)
These people are wrong. The strategy chosen by Rails Core has nothing to do with security through obscurity. It has to do with doing the right thing which is giving users a fair chance at patching their possibly vulnerable system before legions of script kiddies start pounding their servers and hurting their businesses.
So, stop fuzzing and and start patching: gem install rails will do the trick just fine. It only takes a minute and it doesn’t hurt at all !