Re: PHP6, drop open_basedir?
| From: | Pierre Joye | Date: | Wed, 18 Jun 2014 06:29:18 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74970@lists.php.net to get a copy of this message | ||
On Wed, Jun 18, 2014 at 8:05 AM, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
> Hi!
>
>> It gives a false sense of safety, and that alone for me is a good
>> enough reason to remove it. it is not as bad as safe_mode but simply
>> not good.
>
> If you use it right, it does not. Every security feature would give you
> false sense of safety if you use it wrong - but that alone is not the
> reason to not have it at all, if it has legitimate uses. IMO
> open_basedir does.
>
>> That being said I have no issue with keeping it besides the lost
>> opportunity to get rid of an old bad decision.
>
> Bad decision was to brand open_basedir as security function that allows
> defense against attacker with PHP code execution rights. It is obvious
> we can not deliver on this promise. However, it does not mean that used
> differently - e.g. as a safeguard in your own code to not access things
> that you don't want this code to access by mistake - it can not be used.
> I think it can.
This exact example is easily done using system features.
Anyway, we have different views and that's why I started to this
thread, to know other views :)
I will still create a RFC to get an official result on that as all the
users I talked to, as well as security people, consider this feature
as a problem.
Cheers,
--
Pierre
@pierrejoye | http://www.libgd.org