Re: PHP6, drop open_basedir?

From: Date: Wed, 18 Jun 2014 06:29:18 +0000
Subject: Re: PHP6, drop open_basedir?
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-74970@lists.php.net to get a copy of this message
On Wed, Jun 18, 2014 at 8:05 AM, Stas Malyshev <smalyshev@sugarcrm.com> wrote: > Hi! > >> It gives a false sense of safety, and that alone for me is a good >> enough reason to remove it. it is not as bad as safe_mode but simply >> not good. > > If you use it right, it does not. Every security feature would give you > false sense of safety if you use it wrong - but that alone is not the > reason to not have it at all, if it has legitimate uses. IMO > open_basedir does. > >> That being said I have no issue with keeping it besides the lost >> opportunity to get rid of an old bad decision. > > Bad decision was to brand open_basedir as security function that allows > defense against attacker with PHP code execution rights. It is obvious > we can not deliver on this promise. However, it does not mean that used > differently - e.g. as a safeguard in your own code to not access things > that you don't want this code to access by mistake - it can not be used. > I think it can. This exact example is easily done using system features. Anyway, we have different views and that's why I started to this thread, to know other views :) I will still create a RFC to get an official result on that as all the users I talked to, as well as security people, consider this feature as a problem. Cheers, -- Pierre @pierrejoye | http://www.libgd.org

« previous php.internals (#74970) next »