11 ms·
Six of one, half a dozen of the other. http://news.php.net/php.internals/57655 http://news.php.net/php.internals/57655
by sjs 15y ago
Six of one, half a dozen of the other.
http://news.php.net/php.internals/57655 http://news.php.net/php.internals/57655
- rmccue 15y agoThere's a giant disagreement on php-internals at the moment as to the nature of Suhosin. The core developers argue that time would be better spent working on the core itself instead, and Stefan does not agree with that. The aforementioned post is Stefan's attempt to show why suhosin is needed. (I disagree personally, and I think Stefan's attitude is less than productive to the entire discussion.)
- X-Istence 15y agoSeeing as how SuHoSin's patch/extension together stop this flaw from even being exploitable I would say SuHoSin is perfect. Even on PHP 5.3.9 my servers were never exploitable because I utilised the SuHoSin patch/extension with sane defaults. I think any project that doesn't take "security" fixes into consideration, doesn't use code-review and lets developers that clearly have no business changing security sensitive code commit bad code could use a good safe-gaurd that fixes those issues. Yes, the time could be spent working on the core itself, but clearly that won't stop people from committing stuff they shouldn't be committing without having a qualified security guy checking off on it, so that won't help me have a secure running PHP installation...