Ukoliko ste propustili novost, reddit.com je pre dva dana bio žrtva comment worma, u formi persistent XSS napada najopasnijeg od tri tipa XSS-a.
Prema rečima jednog od ljudi odgovornih za održavanje sajta, napad je bio moguć usled toga što je platforma open source tipa.
"As a matter of fact, these bugs were only exploitable because we are open source. The worm author had to scour the source of our output filter to find these holes. We cannot hide behind security though obscurity, and we like it that way."
Hteo sam da napišem svoje mišljenje o ovome, međutim, pronašao sam komentar koji je rekao sve što sam i ja hteo, tako da ovde citiram deo. Ko želi da pročita ceo članak, može da klikne ovde.
"There are a lot of reasons to prefer the open source model, but you are nuts if one of the reasons is that malicious users are more likely to find vulnerabilities. It is true that obscurity does not lead to security - a vulnerability is still there even if no one knows about it. That said, you can reduce risk through obscurity (risk = impact x likelihood, and obscurity reduces likelihood) and that is generally a good thing"