Re: ENFORCE_SAFE_MODE

From: Date: Wed, 30 Aug 2000 20:53:54 +0000
Subject: Re: ENFORCE_SAFE_MODE
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-31319@lists.php.net to get a copy of this message
> Security does come in the price of usability, quite often. The GD issue > alone is a great example of why safe mode is not reliable. What GD issue? I have looked at imageloadfont() and really don't see an obvious exploit here. No security is ever absolute. We have also never advertised safe-mode as being ideal. It does however stop the obvious exploits and is as such useful to a number of people who don't require anything beyond that. Ideally this should not be done at the PHP level at all, but due to lack of better options we needed this stopgap. The better option is something I have been pushing for nearly two years now and it is coming in Apache-2.0. That is the per-VirtualHost user/group configuration setting. I am all for cleaning things up in the current code but lets keep the alarmist messages on this stuff to a minimum. Nothing you said in your message is new. I wrote the same message two years ago. Come up with a better alternative. -Rasmus

« previous php.dev (#31319) next »