Re: PHP6, drop open_basedir?
| From: | Yasuo Ohgaki | Date: | Wed, 18 Jun 2014 22:33:57 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74979@lists.php.net to get a copy of this message | ||
Hi all,
On Tue, Jun 17, 2014 at 6:34 PM, Sebastian Krebs <krebs.seb@gmail.com>
wrote:
> In my experiene it only leads to a false sense of security. I've seen it
> more than once, that people just set a value there and believed, that they
> are now safe. On the other hand they wonder, why many things were broken,
> so they loosen the restrictions again.
>
I agree that many users do not understand what it does and what it's for.
It's a fail safe feature that should not be trusted.
open_basedir should not be trusted, but it does not mean
it's useless just like antivirus softwares. Security features
do not have to be perfect to be useful.
I'm -1 for removing open_basedir.
If there are users who misunderstand what it's for, we
should improve our documentation. IMHO.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net