Re: CVS Account Request

From: Date: Thu, 16 Nov 2000 00:34:28 +0000
Subject: Re: CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38283@lists.php.net to get a copy of this message
At 02:26 16/11/2000, Jim Jagielski wrote:
Zeev Suraski wrote: I don't think it's related, but there is a quality problem. It doesn't come to say that PHP is of poor quality, but it does contain quite a few very poorly written pieces of code, and many bugs. It doesn't mean we're not doing a good job, but it does mean that there's still lots of work to be done... This discussion was not (mainly) about code quality though, but about security. Security can be compromised 2 ways: intentional nefarious code and poorly written or buggy code exploited. :) By definition, I think buffer exploits are due to poorly written code ;) *duck*
Hehe :) You're right, security goes hand in hand with high quality code. It goes back to what kind of QA we have. Functional QA is likely not to spot buffer overflows, because buffer overflows usually result from the coder assuming that the buffer would be big enough, and it usually is, unless you try to exploit it intentionally. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#38283) next »