Re: PHP 5.1
| From: | Gareth Ardron | Date: | Thu, 03 Feb 2005 01:49:29 +0000 |
| Subject: | Re: PHP 5.1 | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-14554@lists.php.net to get a copy of this message | ||
Rasmus Lerdorf wrote:
TCP/IP Firewalls break all sorts of applications as well until either the application is modified to poke a hole in the firewall itself via upnp, or you reconfigure the firewall. This makes firewalls annoying, but they are necessary. This is exactly the same thing. It is a data firewall for PHP. You don't have to use it, but people want it and need it.I would think the difficulty would be in informing people that functionality like this is only the start of good security. Maybe a proper, official, howto on PHP security should be drawn up - or it'll just leave people blindly using things like this. To go back to the firewall analogy, it's like putting the most expensive firewall in the world in place, behind which are a dozen totally unpatched microsoft exchange server and a linux box running bind 8.0. Again, just my 2c. -- Gareth Ardron