Re: Tainted Mode Decision
| From: | Lukas Kahwe Smith | Date: | Mon, 19 Nov 2007 22:45:52 +0000 |
| Subject: | Re: Tainted Mode Decision | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-33338@lists.php.net to get a copy of this message | ||
On 19.11.2007, at 21:50, David Zülke wrote:
Am 18.11.2007 um 22:53 schrieb Lukas Kahwe Smith:This makes no sense to me. There is nothing like 100% secure as long as you dont pull the plug on the entire application. The only secure application is one that hasnt been deployed anywhere. So the question boils down to more "does this increase security sufficiently to make the draw backs acceptable". regards, LukasStefan so what is your point then? Since neither can be 100% secure, do not use any? Or just do not bundle either?Yes, that is exactly the way to go. To quote Yoda (and he would know): "Do, or do not. There is no try.". Or, in contemporary words: do things 100% properly, but if that is not possible, take a step back and spare the world some half arsed attempt.