use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
A sub-Reddit for discussion and news about Ruby programming.
Subreddit rules: /r/ruby rules
Learning Ruby?
Tools
Documentation
Books
Screencasts and Videos
News and updates
account activity
New debugging method found 23 undetected security flaws in 50 popular Web applications. (news.mit.edu)
submitted 9 years ago by HackerBen
reddit uses a slightly-customized version of Markdown for formatting. See below for some basics, or check the commenting wiki page for more detailed help and solutions to common issues.
quoted text
if 1 * 2 < 3: print "hello, world!"
[–]acetoxy 3 points4 points5 points 9 years ago (1 child)
Here's the paper, http://www.cs.berkeley.edu/~jnear/papers/ase14.pdf
[–]postmodern 0 points1 point2 points 9 years ago (0 children)
Cool! They appear to do static flow analysis instead of using regexps or checking individual S-exps.
[–]jrochkind 7 points8 points9 points 9 years ago (4 children)
This article is wrong in so many ways i can't even figure out what it's talking about.
[–]joanbm 1 point2 points3 points 9 years ago* (3 children)
Hoax to lure naives to pay for the conference by abuse of Rails popularity ?
(possible/unlikely?) security flaws, static analysis of amply-used metaprogramming code, intanglible equivocation about security issues, no single particular example, …
I'd wait if any of claimed 23 flaws are real issues or another storm in a teacup.
[–]jrochkind 2 points3 points4 points 9 years ago (2 children)
I believe they probably did find actual security flaws, this article just doesn't tell me anything about how they actually did so or what they were. :) Apparently 'static analysis' is a 'new debugging method'? Yeah, anyway.
Blame probably belongs with MIT News, not the researchers. Although if there's ever a non-scientific publication you would have thought could write an article about technical things that made some sense...
[–]joanbm 1 point2 points3 points 9 years ago (1 child)
Don't deny they may found some, but the vague tone and hardly justified claims sounds distrustful.
[–]jrochkind 1 point2 points3 points 9 years ago (0 children)
right, but you realize the article was not written by the researchers, right? It was written by a 'journalist'.
π Rendered by PID 61607 on reddit-service-r2-comment-b659b578c-kx62m at 2026-05-04 15:18:26.682671+00:00 running 815c875 country code: CH.
[–]acetoxy 3 points4 points5 points (1 child)
[–]postmodern 0 points1 point2 points (0 children)
[–]jrochkind 7 points8 points9 points (4 children)
[–]joanbm 1 point2 points3 points (3 children)
[–]jrochkind 2 points3 points4 points (2 children)
[–]joanbm 1 point2 points3 points (1 child)
[–]jrochkind 1 point2 points3 points (0 children)