Re: Quick Code Audit
| From: | Ron Chmara | Date: | Wed, 06 Sep 2000 07:56:09 +0000 |
| Subject: | Re: Quick Code Audit | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32318@lists.php.net to get a copy of this message | ||
Stanislav Malyshev wrote:
> >> i think it might be a good idea at this time for everyone who actively
> >> develops the PHP language (whether you hack on zend or own a small
> >> module/extension) to work through any outstanding security related issues
> >> as soon as possible. if you're not sure how to fix it, i'm sure other
> >> developers will be all too willing to help you out.
> Well, the idea that code should be audited is definitely good
> idea. However, this couldn't be "quick" - this is slow and sometimes
> painful process.
Hear, hear.
If it's quick, it guaranteed to be missing something. It's a thousand
"quick" thoughts about the code, which adds up to lots and lots of time.
> On the other side, if someone would take on himself to be "security
> watchdog" of PHP and gather and maintain list of known PHP security issues
> - that would be very good.
> --
> Stanislav Malyshev stas@zend.com http://www.zend.com/
> +972-3-6139665 ext.106
Are you volunteering? :-) You do a pretty good job of bull-dogging
(wrestling an issue down... it's a Rodeo term) issues... you certainly
pinned me down to exactitude, more than once....
Or there was that guy who flamed php-dev mightily today, he has that impersonal
ability to attack *all* the code without a friendly eye.... (in this case,
this would be a benefit, no?)
-Bop
--
Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine,
which is currently in MacOS land. Your bopping may vary.