How many more of these are there out there? tens? hundreds? thousands?
How many more of these are there out there? tens? hundreds? thousands?
But on the discussion we had before[1], this one does not seem to affect Rails[2]:
tiegz 14 hours ago | link | parent
Rails has been built around Rack for a couple years, but I think its sessions are safe from this Rack vulnerability. Rails' CookieStore class inherits from Rack::Session::Cookie, but it overwrites the unpacked_cookie_data() method which was open to a timing attack. Rails uses its own MessageVerifier class (https://github.com/rails/rails/blob/master/activesupport/lib...) to do a constant time comparison, which would avoid this attack.
Any other frameworks/libs that use Rack's session cookies should upgrade though, afaik.
In Denmark we often use a payment gateway, exactly to avoid these types of attack. If my webshops database got leaked, my customers would not have to fear creditcard leakage.
I have just often wondered why a lot of the webshops in the US that I use stores all my information, I have never seen it here.
And no, I don't believe that I use more US-based webshops than Danish.
We have laws that you must comply with if you store data: http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Secu...
(This is why I always use a payment gateway and never keep details myself.)
Make the decision to move onto Python seem more correct every day.
See https://www.djangoproject.com/weblog/2011/nov/
This isn't an exactly equivalent situation, since this wasn't a problem with the core Django framework --- but that's in part because the core Django framework does less. Functionality similar to these extensions is bundled with Rails.