Re: Security Issues
| From: | Alexander Wagner | Date: | Fri, 27 Jul 2001 11:18:26 +0000 |
| Subject: | Re: Security Issues | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-61194@lists.php.net to get a copy of this message | ||
Peter Petermann wrote:
> i dont think it is easier to write more secure applications
> with turning a feature of.
In this particular case, it would. There are several reported cases of
security-holes caused by this feature. Without it, there would be fewer
insecure PHP-applications out there.
Thats a fact. Thats the past. Now let's talk about the future.
Turning register_globals off won't fix old code. If code relies on
register_globals, people will "fix" it with foreach (Rasmus' example),
or by turning register_globals on.
But that's not the point. The point is that people who don't care about
security or coding style (beginners or professionals, doesn't really
matter) are less likely to write insecure code, because there's one
mistake less that they can make. As long as they stick to the defaults,
anyway.
regards
Wagner
--
Madness takes its toll. Please have exact change.