Re: Security Diligence

From: Date: Sat, 08 Feb 2014 17:23:21 +0000
Subject: Re: Security Diligence
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-72411@lists.php.net to get a copy of this message
Hi, On 8 February 2014 16:48, Lester Caine <lester@lsces.co.uk> wrote: > Pádraic Brady wrote: >> >> The RFCs do imply some awareness of >> security and that's largely unavoidable unless each and every RFC >> needs to be a 1000 page masterwork;). > > > Since 'security experts' tend not to wait for fixes to be produced before > publishing exploits all I am looking for in this case is enough help in the > rfc's to assess if action is required before fixes ARE published! Good security people will always await fixes before publishing publicly so long as the wait is not unreasonable for the target sample of cases. That's the tendency unless you have data to the contrary? I'm pretty sure those references I provided earlier point at the researchers in each case reporting to open source projects prior to publishing their research. Obviously, researchers can't report to every single open and closed source library and app that exists but they do make a best effort to get the word out. > And I hope that since these are security fixes that they are pushed back as > far as PHP5.3 since this is still under support for security fixes? It is > even more important if the fixes are not being rolled back that the extent > of the risk is recorded well enough for users to understand the risk? These are not vulnerabilities within PHP but in userland code. The RFCs will make it easier for userland code to be secure out of the box, but userland code should already have such issues patched. I don't see any reason to backport the RFCs unnecessarily - you can make arguments for adding anything useful to older versions not just for security. Paddy -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative

« previous php.internals (#72411) next »