4 ms·
I install PHP on my server (yeah I know) to run some PHP based web based software. By default PHP is configured in a very insecure manner. You would think with
by davesmith1983 7y ago
I install PHP on my server (yeah I know) to run some PHP based web based software. By default PHP is configured in a very insecure manner. You would think with all the security problems that they would ship it with a set of secure defaults.
- overcast 7y agoProblem with setting secure defaults, is that most of the worlds PHP would stop working properly.
- davesmith1983 7y agoProbably but you can still have the configuration secure as default and people would be aware of the security implications when enabling insecure features.
- naniwaduni 7y agoNo, that would be a breaking change.
- AlphaSite 7y agoJava did that with modules and it appears to have worked ok for them.
- overcast 7y agoYou're vastly overestimating the technical capabilities of the average person installing or creating software.
- davesmith1983 7y agoI am talking about whoever is packaging PHP for the OS, there is a default php.ini that comes with PHP on CentOS is insecure by default (I can't remember off the top of my head which settings were set to something insecure). We are talking about an ini file. This isn't rocket science.
- overcast 7y agoRight, but they need to be conscious of their end user. If they secure by default, and someone upgrades, their software stops working. Should PHP have had these defaults to begin with, yes absolutely. But now we're all stuck with a million miles of code that will break if register_globals is turned off. That's the point. Everything you've stated above there might as well be an alien language to the majority of people using this stuff.
- davesmith1983 7y agoNo it should be secure by default and people will have to enable insecure features. It doesn't stop old software from working as the person will be able to simply re-enable whatever the insecure feature is. However they will now be aware that said feature is insecure and should know the consequences of enabling it.