Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
lucian1900
on March 7, 2012
|
parent
|
context
|
favorite
| on:
SSH Key Audit on Github (required)
It most certainly is a vulnerability in rails, by encouraging bad practice by design. Mass assignment should work by defaulting attributes to protected, if it should exist at all.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: