Re: Security Diligence
| From: | Pádraic Brady | Date: | Sat, 08 Feb 2014 17:23:21 +0000 |
| Subject: | Re: Security Diligence | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72411@lists.php.net to get a copy of this message | ||
Hi,
On 8 February 2014 16:48, Lester Caine <lester@lsces.co.uk> wrote:
> Pádraic Brady wrote:
>>
>> The RFCs do imply some awareness of
>> security and that's largely unavoidable unless each and every RFC
>> needs to be a 1000 page masterwork;).
>
>
> Since 'security experts' tend not to wait for fixes to be produced before
> publishing exploits all I am looking for in this case is enough help in the
> rfc's to assess if action is required before fixes ARE published!
Good security people will always await fixes before publishing
publicly so long as the wait is not unreasonable for the target sample
of cases. That's the tendency unless you have data to the contrary?
I'm pretty sure those references I provided earlier point at the
researchers in each case reporting to open source projects prior to
publishing their research. Obviously, researchers can't report to
every single open and closed source library and app that exists but
they do make a best effort to get the word out.
> And I hope that since these are security fixes that they are pushed back as
> far as PHP5.3 since this is still under support for security fixes? It is
> even more important if the fixes are not being rolled back that the extent
> of the risk is recorded well enough for users to understand the risk?
These are not vulnerabilities within PHP but in userland code. The
RFCs will make it easier for userland code to be secure out of the
box, but userland code should already have such issues patched. I
don't see any reason to backport the RFCs unnecessarily - you can make
arguments for adding anything useful to older versions not just for
security.
Paddy
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative