There's been a lot of anger around Twitter on this. I've also seen a lot of people cherry-picking a non-native speaker's words out of context too. Specifically, "Ruby is not a project for security."
That doesn't mean that this bug is not important, or that the Ruby team's decision as it currently stands is a good one. But it's a complex issue.
"It's a complex issues" == Ruby Security Fails again.
It is a crackers dream that so much Ruby code is being exposed to the web these days. Such low hanging fruit. Even the script kiddies laugh at the ease of compromise.
Did you actually read the context of that quote, which happens to communicate almost exactly the opposite of what you're inferring (and implying by quoting it out of context)?
Non-SSL expert here and first time poster (not trolling). Python also uses a wrapper for OpenSSL and has similar issues with default settings. Is this problem specific to Ruby or also Python apps as well?
This also applies to Python. For example, Python recently disabled SSLv2. Someone filed a bug and the fix was committed within 3 hours. http://bugs.python.org/issue20207
[+] [-] steveklabnik|12 years ago|reply
That doesn't mean that this bug is not important, or that the Ruby team's decision as it currently stands is a good one. But it's a complex issue.
[+] [-] coherentpony|12 years ago|reply
[+] [-] insecure_ruby|12 years ago|reply
It is a crackers dream that so much Ruby code is being exposed to the web these days. Such low hanging fruit. Even the script kiddies laugh at the ease of compromise.
Sigh.
[+] [-] state_machine|12 years ago|reply
That's from ruby-core. That's a frightening attitude for a project to take.
[+] [-] dperfect|12 years ago|reply
[+] [-] est|12 years ago|reply
[+] [-] dontuseruby|12 years ago|reply
Security - they've heard of it, at least now.
[+] [-] ces1|12 years ago|reply
[+] [-] sanxiyn|12 years ago|reply
[+] [-] tptacek|12 years ago|reply
[+] [-] briansmith|12 years ago|reply
[+] [-] lobster_johnson|12 years ago|reply
[+] [-] pixl97|12 years ago|reply
https://www.ssllabs.com/projects/best-practices/index.html
[+] [-] girvo|12 years ago|reply