Re: Quick Code Audit
| From: | Lars Torben Wilson | Date: | Wed, 06 Sep 2000 08:22:17 +0000 |
| Subject: | Re: Quick Code Audit | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32320@lists.php.net to get a copy of this message | ||
Ron Chmara writes:
> Are you volunteering? :-) You do a pretty good job of bull-dogging
> (wrestling an issue down... it's a Rodeo term) issues... you certainly
> pinned me down to exactitude, more than once....
>
> Or there was that guy who flamed php-dev mightily today, he has that impersonal
> ability to attack *all* the code without a friendly eye.... (in this case,
> this would be a benefit, no?)
>
> -Bop
Well, as long as it stays to attacking the *code* and not the
*author*. :)
That fellow seems so stuck in schoolyard tactics and willingness to
slag others that I, at least, am willing to put little more stock in
his mental prowess than in his emotional. I mean, he did raise valid
points and all, but he also raised a lot of invalid points and threw
in quite a lot of subjective detritus.
Stanislav, on the other hand, at least makes points fairly and with
honour (OK, I've been reading Narnia again :). Lots of people on these
lists are like that. Sometimes it gets a bit rough, but today was
truly exceptional. Blunt is fine--that little display of Ribbens'
today is, IMHO, not.
But we do need folks who are willing to say what needs to be said
about security and other problems. And it's not good to hold back
'cause somebody might get hurt feelings. But it can always be
alleviated to some degree.
Oops--a bit OT there. Umm...security audit! Yes! But...I don't think
this is really the sort of thing that can be spoken about as if the
project might have an end: as long as PHP exists, it seems, the audit
must continue.
And it sounds like something that would fall under the umbrella of the
QAT folks...or else a new group (PHP|SAT anyone? :) (Security Assessment
Team).
Perhaps a more formal introduction and reference on programming PHP 4
internals would be good: give folks who are writing extensions or
hacking closer to the core an idea of what sorts of things to try to
keep in mind, as well as a good understanding of how to best use the
internal framework(s) for consistency and ease of proofreading
(auditors/documentors both need to do this).
Just my $0.02CDN.
--
+----------------------------------------------------------------+
|Torben Wilson <torben@php.net> Netmill iTech|
|http://www.coastnet.com/~torben http://www.netmill.fi|
|Ph: 1 250 383-9735 torben@netmill.fi|
+----------------------------------------------------------------+