[mythtv-users] Bug: Large listings not displayed in mythweb
Michael Starks
mythtv at michaelstarks.com
Thu Mar 11 17:24:22 EST 2004
Chris Petersen wrote:
>>In addition, path disclosure is not necessarily a good thing. These
>>kinds of messages should be sanitized.
>
>
> Why? Do you let the world see your mythweb box? It's easy enough to
> suppress them, but I can't think of any reason NOT to secure a mythweb
> box, and since most people won't be hooking up the error email address,
> showing the errors to the browser is the best way to get bug reports.
>
No, I don't allow world access to my Myth box. Why? Because it's
obvious that security is not a prime objective in Myth. I understand that.
That being said, I do think that as we move into an age where appliances
have TCP stacks, we're going to regret not making these apps secure by
design.
I do understand your point, though.
More information about the mythtv-users
mailing list