Re: Self Destruct code
| From: | PHPCoder | Date: | Wed, 08 May 2002 06:55:03 +0000 |
| Subject: | Re: Self Destruct code | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-96539@lists.php.net to get a copy of this message | ||
Fellow PHP'ers
Firstly, thank you for the responses, seems to be a subject that most people have touched, yet, unfortunately, it seems that there are no fool proof tried and tested method out there.
Much of the advise given are perfectly acceptible and make plenty of sence, yet, even if you keep the code on your own server and demo the app, they still might insist on payment AFTER you have given the complete product ( I can also understand this, when I buy something, I would also like to have the product before I give the money). In my case, I CANNOT keep any part of the app on my own servers as the app is intended to run on an intranet with no outside connections, so I am basically spoofed with anything to do with keeping part on my own servers or creating a backdoor.
In previous cases I have built myself an inconspicuous page between the rest that simply runs eval() on the posted var, allowing me to break things if needed, but even that will not work if the client puts .htpassword on his site ( most of the stuff I do is intended for company only use and not for the general public, so most sites are heavily password protected).
Even building time locks into the code can prove to be pointless as it doesn't take a genius to read through the code to see where you are "disabling" it. So, that leaves the contract as my only and last resort...
Firstly, my problem with contracts being my safety net: I am not a lawyer, don't want to be, and don't have the time to go to court. Secondly, lawsuits can be dragged out over several years depending on the amount and parties involved, and the problem is, some clients know this and deliberately try to exploit this.
So, from all the responses to this thread, I can see that all of us are in the same boat, granted, not all clients have this attitude, and most are recurring clients that understand how business works, however, most of us are not in the priveleged position to pic and choose jobs, which leaves me to believe that we ( the PHP coders of the world) need some protection. Now this can start a Holy War, with people arguing that the only real solution is encryption of code in order to hide cripling code or other means to protect yourself, and hence, there goes the whole Open Source idea ( which, believe me, I am NOT trying to do ), but on the other hand, encrypted code for paid products to clients aren't supposed to become part of the world wide php code library.
Which brings me to the question, shouldn't we start a project that addresses this problem? I am aware of the dangers of having a "free" Zend encoder; what will prevent people from encrypting everything they do, and hence cause the PHP community to suffer from this ( possibly?), but I believe that this community has been here long enough and we have enough dedicated open source people who knows what it's all about to sustain it even if there were such dangers lurking.
I think this needs much more thought and much more input from others.
Again, I am not trying to shoot down the suggestions about having a sound legal contract and regular billing etc, I am just playing devil's advocate and looking at the worst case for the "smaller" developers that are left to the wolves. I shudder to think how many people have been conned out of their hard work and how much damage that can cause small businesses depending on any and all means of income. Personally I think that PHP will become an even more popular language if people know they have some built in assurance; in the end it all comes down to money doesn't it
? We all have to eat right?
Thanks alot for hearing me out, lokking forward to your responses
Petre
SP wrote:
Although the database server would be located on your server, the username and password would be visible in the code so they could use phpmyadmin and get the whole database - structure and data. -----Original Message----- From: tcarney@selterra.com [mailto:tcarney@selterra.com] Sent: May 7, 2002 7:35 PM To: PHPCoder Cc: php-general Subject: Re: [PHP] Self Destruct code On Tue, 7 May 2002, PHPCoder wrote:I have a funny request; I wrote a system for a client and am rather concerned that I am not going to receive payment for the work done. They want me to hand over the code before they are willing to pay, so basically I will be left at their mercy; if they don't pay, they will still have a working version of the system...If you really have the need to protect yourself I would install the application on a staging machine and demonstrate it to the client from there and if they are satisified then you can transfer it to the final location when payment is received. Another alternative would be to install the application on their system but use a database server on a system that you control making sure you keep the table structures you used to initialize the db to yourself. You can then move it seamlessly to the actual server when you (and they) are happy. If they don't pay you can block the application fro accessing your database server and all they'll have is the application with no practical way to recreate the tables thus rendering it useless to them. This way if the mail is late or there is an unintentional misunderstanding you won't find yourself unfairly alienating an otherwise valuable client. Regards, Terry. tcarney@selterra.com ---------------------------------------------------------- Public PGP Key: http://www.selterra.com/pgpkey/tcarney.asc -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php