Re: Re: Windows Peer Verification
| From: | Pádraic Brady | Date: | Mon, 03 Feb 2014 23:41:02 +0000 |
| Subject: | Re: Re: Windows Peer Verification | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72157@lists.php.net to get a copy of this message | ||
Hi,
On 3 February 2014 22:17, Sanford Whiteman
<swhitemanlistens-software@cypressintegrated.com> wrote:
> I think you need to get more experience with the range of third-party
> code that doesn't turn on verify_peer. And frankly it is PHP's fault
> that most code doesn't do so, since PHP was insecure by default and
> never threw an error in the past. Heaping blame on library authors is
> absurd. If someone is writing to the Twitter API, they might not know
I'm sorry, but this is simply outrageous. It is a programmer's
responsibility to code securely. It's not absurd, it's reality. If you
can't program securely, you shouldn't be programming. This is not some
fantasy world where I should pity programmers for their ignorance.
It's a world were security flaws can cost companies money, endanger
user's privacy and THEIR money, where even minor mistakes can have
devastating consequences to privacy and compliance with national and
international laws. I fire programmers who can't learn secure coding,
but thankfully that's almost unheard of ;). A little training goes a
long way. My next favourite excuse is the one where Man-In-The-Middle
attacks are rare theoretical occurances and so why bother - a belief
in utter defiance of how the internet works. I bet the NSA gets a real
chuckle out of that one. What's the next excuse? Right, it's all PHP's
fault.
Your blaming of PHP is significantly misplaced. It is not solely
responsible for programmer malpractice. There are programmers out
there, right this moment, with code all across Github doing one very
unusual thing. They are deliberately disabling peer verification in
cURL where it is enabled by default. They WILL do the same with PHP
streams/sockets. The buck stops at the programmer's feet and that's
it. All PHP can do is promote and encourage best practices, it can
never enforce them.
Paddy
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative