Re: open_basedir?

From: Date: Tue, 07 May 2019 19:08:34 +0000
Subject: Re: open_basedir?
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-105633@lists.php.net to get a copy of this message
Hi! > If scenario (a) gives even a slight security advantage over scenario (b), > we should think very carefully before removing the feature. There's definitely _some_ security advantage, defense is always in layers, and while open_basedir can not be made secure, it certainly can avert _some_ attacks and prevent _some_ bugs from becoming a security catastrophe. *Relying* on it is wrong, but using it while being fully aware it is just a partial protection that is only good for certain things but not others is IMO fine. -- Stas Malyshev smalyshev@gmail.com

« previous php.internals (#105633) next »