lua-users home
lua-l archive

[Date Prev][Date Next][Thread Prev][Thread Next] [Date Index] [Thread Index]


It was thus said that the Great Roberto Ierusalimschy once stated:
> > [...]
> > And I'm not saying *don't* bother with security at all.  I'm just tired of
> > the knee-jerk reaction of "let's do this because security!" leaving people
> > with the illusion of security when they aren't.  Understand the threat
> > model.  Just because you have ASLR and don't print addresses doesn't make
> > you safe from exploits.
> 
> +1. Thanks! :-)

  And an amusing bit of security knee-jerk reactions from another mailing
list I'm on:

> I heard from one user whose ISP is blocking incoming port 80 (everything
> can be reasoned with "security" nowadays).

  -spc (BLOCK ALL THE PORTS!)