[Zope-dev] How (in)secure is Zope?

Christian Tismer tismer@tismer.com
Thu, 13 Mar 2003 01:54:20 +0100


Dear Zope community,

please excuse my ignorance, but I am asked
from time to time how secure or insecure
Zope actually is, and I always have to say
that I actually don't know.

There are people claiming that Zope opens a system
to quite some level, others claim the opposite.

Can someone please enlighten me and give me some
details? Especially, are there some Zope products
considered especially "insecure"?

And, pondering more on security, are these issues,
if they exist, bounded to Zope itself, or becomes
a system generally more "open" to attacks, after
Zope was installed?

I don't mean to offend anybody by this, it is just
a very simple question which I cannot answer alone.

thanks so much in advance -- chris

-- 
Christian Tismer             :^)   <mailto:tismer@tismer.com>
Mission Impossible 5oftware  :     Have a break! Take a ride on Python's
Johannes-Niemeyer-Weg 9a     :    *Starship* http://starship.python.net/
14109 Berlin                 :     PGP key -> http://wwwkeys.pgp.net/
work +49 30 89 09 53 34  home +49 30 802 86 56  pager +49 173 24 18 776
PGP 0x57F3BF04       9064 F4E1 D754 C2FF 1619  305B C09C 5A3B 57F3 BF04
      whom do you want to sponsor today?   http://www.stackless.com/