Re: Security Diligence
| From: | Lester Caine | Date: | Sat, 08 Feb 2014 16:17:40 +0000 |
| Subject: | Re: Security Diligence | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72406@lists.php.net to get a copy of this message | ||
Pierre Joye wrote:
Currently the material in question is being discussed on this list, and some people obviously understand what the risks are and when pressed pass on that information, but we should not have to ask for clarification. That material should be the basis of the rfc that is being discussed! If the very basis of a problem is not documented then how can it be signed off? The details have been fairly well covered on this list, but moving it forward it needs to be reflected in the documentation. Your own changes to selection of random number sources is quite complex and perhaps we don't need to understand the details, but it should be easier to access direct from the documentation rather than having to interpret third part documents. Simply linking those third part documents may be all that is needed, but how often do they become unavailable later ... wikipedia have killed a number of software related articles. Perhaps when I've managed to get all of not only my own code but other peoples code into a state where it will run on a modern PHP installation, then I might actually be able to find time to put my own improvements forward. My current contribution is as it always has been ... trying to help users get up to date with a continually moving target :( The latest 'problems' are just taking time I don't have to check through if there even is a problem. It will be fixed in a later version of PHP but nowadays that is just not good enough for some people :( I am NOT trying to maintain PHP5.2, it is just there is still a large volume of material that despite what others seem to think will not 'just run' on even 5.3 and now we are getting new 'risks' which may need patching in code that has been updated. If there was an easier way of 'upgrading' then there would not be such a backlog of code still needing converting? -- Lester Caine - G8HFL ----------------------------- Contact - http://lsces.co.uk/wiki/?page=contact L.S.Caine Electronic Services - http://lsces.co.uk EnquirySolve - http://enquirysolve.com/ Model Engineers Digital Workshop - http://medw.co.uk Rainbow Digital Media - http://rainbowdigitalmedia.co.ukMuch of the difficulty I have with PHP these days is simply trying tounderstand why the 'new' method of working is better than what we did 10 or more years ago. Good examples of practice is still very lacking even in the latest documentation, and what goes into rfc's these days is the basis for updating the main documentation? Lester, this is not a support list. It is your good right to stick with dead PHP versions and 10 years old code (whether it is your choice or not), but it is definitively not good to constantly posts totally off topic posts, replies or complains about what we do or don't. It is even more annoying in cases where you clearly do not understand the underlying reasons of one feature or another. That being said, I would love to see you actually contribute something for a change.