SpreadFirefox Security Breached (again)
Kurt writes "The hugely popular SpreadFirefox project, a Firefox community marketing site, has recently fallen victim to a security breach in their TWiki software. This breach has forced the site to shutdown until October 19th. During this time, they will be performing a rebuild of the SpreadFirefox system, to hopefully curb more security breaches."
Posted by CmdrTaco on Wednesday December 31, @09:00PM
I think Slashdot editors have finally gone of the deepend.
I was wondering who beat me out of the time machine on Ebay.
Don't forget the crystals Taco! THE CRYSTALS!
Fractured Element
In Croatia, artist Sinisa Labrovic has launched a satire of reality shows, starring sheep instead of people. After a 10-day competition, the winning sheep will be honored with poetry. The losers will be eaten.
"Speaking the Truth in times of universal deceit is a revolutionary act." -- George Orwell
While it is certainly easy to use regular expressions in this manner to produce code that qualifies as poor engineering from a security standpoint, the regular expressions that SpreadSheetPlugin uses are actually simple enough to be easily verifiable, or would be if they reduced their excessive use of backslashes down to something readable.
For instance, I would rewrite the first half of their safeEvalPerl subroutine as:I will admit that the excessive use of eval elsewhere in that module (why are they using the string form of eval, and not the block form?) gives me the security heebie-jeebies. Every spot I found was good, but I had to check too closely.
In your "For Developers" section I would add these suggestions: