[mythtv-users] Bug: Large listings not displayed in mythweb

Michael Starks mythtv at michaelstarks.com
Thu Mar 11 17:24:22 EST 2004


Chris Petersen wrote:

>>In addition, path disclosure is not necessarily a good thing.  These 
>>kinds of messages should be sanitized.
> 
> 
> Why?  Do you let the world see your mythweb box?  It's easy enough to
> suppress them, but I can't think of any reason NOT to secure a mythweb
> box, and since most people won't be hooking up the error email address,
> showing the errors to the browser is the best way to get bug reports.  
> 

No, I don't allow world access to my Myth box.  Why?  Because it's 
obvious that security is not a prime objective in Myth.  I understand that.

That being said, I do think that as we move into an age where appliances 
have TCP stacks, we're going to regret not making these apps secure by 
design.

I do understand your point, though.



More information about the mythtv-users mailing list