3 ms·
I'm at least trying to understand you. But i still say, if you expect a string from a query (address bar) but you don't type-check it before using it somewhere
by ayi 13y ago
I'm at least trying to understand you.
But i still say, if you expect a string from a query (address bar) but you don't type-check it before using it somewhere, it's your problem not php's. (by the way i'm a ruby programmer in my 9-5 work)
- btilly 13y agoWhat you are saying is that it is your problem if you do not know PHP well enough to know everything that it is going to possibly do behind your back. And you say that in full knowledge of the fact that PHP is widely used by the exact kind of novice programmer who are least likely to be able to competently do that. And you fail to notice that those two facts combine for a recipe for a constant stream of security holes. Figure those things out, and then you will understand why I think that PHP is worse for security than other languages.
- ayi 13y ago"RTFM" is the correct response in this situation. PHP converts []s in url to arrays. You should know that, because you are the programmer. You should know your language. What if i send "anything' OR 'x'='x" as parameter? Does SQL injection also PHP's fault or does it programmer's?
- btilly 13y agoWhen you compare with other languages, PHP does a lot more behind the programmer's back, has a far larger set of built-in functions (many of which have bad interactions) and has a user base with on average less experienced programmers. And yet you think that RTFM is the answer. Yes, programmers need to RTFM. Security isn't free. But PHP makes it much, much harder than it should be. And does so with a base of users who are not prepared to do it well. If you want to get real security, you don't get it by simply saying, "Bad developer!" You do it with layering defenses. Developers who know what they are doing, using APIs that are clearly defined, with languages that do not introduce unnecessary potential security issues, with development practices that catch issues, with monitoring that notices stuff, and so on and so forth. Yes, developers should RTFM. But if RTFM is the beginning and end of your thinking, you've got disasters waiting to happen. And the results are abundantly clear with PHP. Now I'm done with this conversation. You are missing what should be a pretty basic and obvious point. PHP makes security harder than it should be. Not impossible. But harder than it should be.