Re: Re: Windows Peer Verification

From: Date: Mon, 03 Feb 2014 23:41:02 +0000
Subject: Re: Re: Windows Peer Verification
References: 1 2 3 4 5  Groups: php.internals 
Request: Send a blank email to internals+get-72157@lists.php.net to get a copy of this message
Hi, On 3 February 2014 22:17, Sanford Whiteman <swhitemanlistens-software@cypressintegrated.com> wrote: > I think you need to get more experience with the range of third-party > code that doesn't turn on verify_peer. And frankly it is PHP's fault > that most code doesn't do so, since PHP was insecure by default and > never threw an error in the past. Heaping blame on library authors is > absurd. If someone is writing to the Twitter API, they might not know I'm sorry, but this is simply outrageous. It is a programmer's responsibility to code securely. It's not absurd, it's reality. If you can't program securely, you shouldn't be programming. This is not some fantasy world where I should pity programmers for their ignorance. It's a world were security flaws can cost companies money, endanger user's privacy and THEIR money, where even minor mistakes can have devastating consequences to privacy and compliance with national and international laws. I fire programmers who can't learn secure coding, but thankfully that's almost unheard of ;). A little training goes a long way. My next favourite excuse is the one where Man-In-The-Middle attacks are rare theoretical occurances and so why bother - a belief in utter defiance of how the internet works. I bet the NSA gets a real chuckle out of that one. What's the next excuse? Right, it's all PHP's fault. Your blaming of PHP is significantly misplaced. It is not solely responsible for programmer malpractice. There are programmers out there, right this moment, with code all across Github doing one very unusual thing. They are deliberately disabling peer verification in cURL where it is enabled by default. They WILL do the same with PHP streams/sockets. The buck stops at the programmer's feet and that's it. All PHP can do is promote and encourage best practices, it can never enforce them. Paddy -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative

« previous php.internals (#72157) next »