develooper Front page | perl.qa | Postings from November 2008

Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists

Thread Previous | Thread Next
From:
Michael G Schwern
Date:
November 12, 2008 19:16
Subject:
Re: [PATCH] ExtUtils::MakeMaker and world writable files in dists
Message ID:
491B9BF3.2020601@pobox.com
David Golden wrote:
> On Wed, Nov 12, 2008 at 3:17 PM, demerphq <demerphq@gmail.com> wrote:
>> I rather strongly object to this change.
> 
> I totally understand -- but keep in mind that this was in response to
> someone flagging this as a potential (if highly unlikely) security
> hole, forwarding it to some security-watchdog site, etc.  So the rapid
> response was "close the hole so no one can say CPAN creates a security
> risk".  (Other than the usual, obvious one of running arbitrary
> code...)
> 
> So it causes some pain, but in my view, it's in the interest of the
> Perl community to be seen as vigilant.

I'm sorry, you'll have to remove your shoes before you can post to this
mailing list.

http://en.wikipedia.org/wiki/Security_theater


-- 
Stabbing you in the face for your own good.

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About