RE: [PHP-DEV] Bringing the 'include' discussion to an end

From: Date: Tue, 12 Jul 2005 04:11:14 +0000
Subject: RE: [PHP-DEV] Bringing the 'include' discussion to an end
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-17235@lists.php.net to get a copy of this message
David Zülke writes: > I don't care about the thousands of idiots out there who are too > dumb to avoid security leaks. You don't have to be very dumb to create a whopping big security hole. It should be *hard* to create a security lapse which causes hostile code to run on your server. 'include' makes it trivial. > The discussion is stupid, and it did nothing but waste helluva lot > of bandwidth. Actually ... this discussion established firmly that PHP's insecurity is designed-in as a _feature_. Anybody reading the archives will understand that PHP and security will forever be strangers to each other. Sorry, Rasmus, for calling a spade a spade, but it needs to be said even if you don't like it. -- --My blog is at blog.russnelson.com | If you want to find Crynwr sells support for free software | PGPok | injustice in economic 521 Pleasant Valley Rd. | +1 315-323-1241 | affairs, look for the Potsdam, NY 13676-3213 | | hand of a legislator.

« previous php.internals (#17235) next »