Re: Re: Windows Peer Verification

From: Date: Tue, 04 Feb 2014 00:29:29 +0000
Subject: Re: Re: Windows Peer Verification
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-72161@lists.php.net to get a copy of this message
Hi, On 3 February 2014 23:56, Sanford Whiteman <swhitemanlistens-software@cypressintegrated.com> wrote: >> I'm sorry, but this is simply outrageous. It is a programmer's >> responsibility to code securely. It's not absurd, it's reality. If >> you can't program securely, you shouldn't be programming. > > No, the reality is that (most) PHP users (most of whom are consuming > someone else's code to some degree) assume that making an SSL > connection means "secure." > > It is absurd to claim otherwise. In fact, _we are agreeing that that > assumption should always have been correct_ by changing the default > behavior in PHP! > > How can you possibly "blame" users and "fix" the behavior at the same > time? Hello. I am a programmer. Sorry, but oopsie, that script I wrote to retrieve client data from our remote office? Well, I sort of forgot to configure SSL correctly and, well, somebody dumped a whole list of client names, emails, social security numbers and other personally identifiable information onto a file dump site. I'm really really sorry. It's all PHP's fault. FIRED! FIRED! FIRED! :P I blame programmers for security problems because it's their fault. Anyone who can't take personal responsibility needs to grow up and own up. Programmers aren't, at least in a professional capacity, children anymore. This whole attitude of avoiding responsibility by pointing fingers at anything else is the one thing that drives security people demented. >> Your blaming of PHP is significantly misplaced. > > No, it is not. We'll have to agree to disagree about who gets blamed when hackers strike. > If it were, this patch would not exist, for it has ALWAYS been > possible to create a peer-verified outbound connection from PHP. > > You cannot at once place blame only on the developer and make a core > change so the language is "the way it should always have been." You missed the cURL part of my last email, I presume... -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative

« previous php.internals (#72161) next »