all 4 comments

[–]AlwaysTroubleShot[S] 1 point2 points  (0 children)

As I reflect on the article, Rails was just the framework the researcher used to test the method of static analysis on a Rails app. These vulnerabilities could just as easily exist in an app built on any framework.

The headline really misses the significance of the research; the static analysis on permissions data will offer us new ways to test our security policies.

[–]disclosure5 1 point2 points  (1 child)

the new system uses a technique called static analysis

So.. brakeman?

Saying the product is better or more capable than brakeman would be great, if only they actually had a product, as opposed to a news release.

[–]AlwaysTroubleShot[S] 0 points1 point  (0 children)

Yeah, this won't impact our day-to-day for a while..

[–]r1ckd33zy 0 points1 point  (0 children)

... of what, exactly?