Exploiting symlinks and tmpfiles
Posted Sep 20, 2007 11:58 UTC (Thu) by nix
In reply to: Exploiting symlinks and tmpfiles
Parent article: Exploiting symlinks and tmpfiles
Way too late. I mean, even the insecure pre-stdio gets() function is still around, decades after deprecation.
This is the downside of code reuse and common interfaces: it's very hard to change stuff once it's been widely used. (This seems to be a common trait in all sorts of complex systems: consider the degree of conservation of ancient regulatory systems in metazoan genetics, for instance, simply because once it's set up it's too hard to change. Building foundations is easy: changing them once a house is built on top is really difficult.)
to post comments)