mysticgalaxies team mailing list archive
-
mysticgalaxies team
-
Mailing list archive
-
Message #00018
Re: Python :(
We've already had to disable a few builtin functions, such as file (which
could open a local file for reading/writing), worth noting is that also
import is disabled, did you bring this up when you asked, Braden?I think
disabling import should save us from most security headaches (other than
builtin functions, but that's a relatively small list)
Though if we're gonna dump Python we'll have to find another candidate
quick, what do you say about Lua?
Here's a list of languages that are good for embedding, though without any
consideration for security in arbitrary code,
http://en.wikipedia.org/wiki/Categorical_list_of_programming_languages
2009/5/27 Ted Smith <teddks@xxxxxxxxx>
> Insecure how?
>
> On Tue, 2009-05-26 at 19:33 -0400, Braden Walters wrote:
> > I asked the Python community about what they think about using Python
> > for a project like Amethyst. They said it's WAY too insecure. I suppose
> > it's best to go back now before we get too far into a mess. Since this
> > is mostly for Rakhun, I'll have to talk to you in IRC some time about
> > this.
> >
> >
> > _______________________________________________
> > Mailing list: https://launchpad.net/~mysticgalaxies
> > Post to : mysticgalaxies@xxxxxxxxxxxxxxxxxxx
> > Unsubscribe : https://launchpad.net/~mysticgalaxies
> > More help : https://help.launchpad.net/ListHelp
>
> _______________________________________________
> Mailing list: https://launchpad.net/~mysticgalaxies
> Post to : mysticgalaxies@xxxxxxxxxxxxxxxxxxx
> Unsubscribe : https://launchpad.net/~mysticgalaxies
> More help : https://help.launchpad.net/ListHelp
>
>
Follow ups
References