3 ms·
"RTFM" is the correct response in this situation. PHP converts []s in url to arrays. You should know that, because you are the programmer. You should know your
by ayi 13y ago
"RTFM" is the correct response in this situation. PHP converts []s in url to arrays. You should know that, because you are the programmer. You should know your language. What if i send "anything' OR 'x'='x" as parameter? Does SQL injection also PHP's fault or does it programmer's?
- btilly 13y agoWhen you compare with other languages, PHP does a lot more behind the programmer's back, has a far larger set of built-in functions (many of which have bad interactions) and has a user base with on average less experienced programmers. And yet you think that RTFM is the answer. Yes, programmers need to RTFM. Security isn't free. But PHP makes it much, much harder than it should be. And does so with a base of users who are not prepared to do it well. If you want to get real security, you don't get it by simply saying, "Bad developer!" You do it with layering defenses. Developers who know what they are doing, using APIs that are clearly defined, with languages that do not introduce unnecessary potential security issues, with development practices that catch issues, with monitoring that notices stuff, and so on and so forth. Yes, developers should RTFM. But if RTFM is the beginning and end of your thinking, you've got disasters waiting to happen. And the results are abundantly clear with PHP. Now I'm done with this conversation. You are missing what should be a pretty basic and obvious point. PHP makes security harder than it should be. Not impossible. But harder than it should be.