Re: Security Issues

From: Date: Fri, 27 Jul 2001 11:18:26 +0000
Subject: Re: Security Issues
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-61194@lists.php.net to get a copy of this message
Peter Petermann wrote: > i dont think it is easier to write more secure applications > with turning a feature of. In this particular case, it would. There are several reported cases of security-holes caused by this feature. Without it, there would be fewer insecure PHP-applications out there. Thats a fact. Thats the past. Now let's talk about the future. Turning register_globals off won't fix old code. If code relies on register_globals, people will "fix" it with foreach (Rasmus' example), or by turning register_globals on. But that's not the point. The point is that people who don't care about security or coding style (beginners or professionals, doesn't really matter) are less likely to write insecure code, because there's one mistake less that they can make. As long as they stick to the defaults, anyway. regards Wagner -- Madness takes its toll. Please have exact change.

« previous php.dev (#61194) next »