develooper Front page | perl.perl5.porters | Postings from July 2008

Re: Creative and *routine* use of so-called "magic" ARGV (was[perl #2783] Security of ARGV using 2-argument open)

Thread Previous | Thread Next
From:
Abigail
Date:
July 29, 2008 00:29
Subject:
Re: Creative and *routine* use of so-called "magic" ARGV (was[perl #2783] Security of ARGV using 2-argument open)
Message ID:
20080729072913.GM30221@almanda
On Tue, Jul 29, 2008 at 01:08:21AM -0400, Mark Mielke wrote:
>
> If I want to write a secure application, I'm not sure I would choose  
> Perl. If I did use Perl, or any other language, I would expect to have  
> to put in effort and have a clue.


I wouldn't expect anyone to write a non-trivial secure application without
having to put in effort and having a clue. Regardless of the language.

But if you think this is an important issue, wouldn't it make much
more sense to teach people RIGHT NOW that they shouldn't rely on while (<>)
automatically open files for them, then to wait a couple of years before
5.12 is released, and then a few more years before everyone has upgraded
to 5.12?



Abigail

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About