Hacker News new | past | comments | ask | show | jobs | submit login

He discovered a major vulnerability in github and pointed it out by making a commit to the rails master repository (which has rather obvious serious repercussions from a security standpoint).



My recollection (though I don't know much about rails and this is just going from memory) is that he attempted to make an argument to the rails team for more secure defaults in parameter parsing and for the framework to steer apps towards more secure use. When they brushed him off and said it was ultimately the caller's responsibility to use it right, he exploited github to make his point.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: