Re: PHP6, drop open_basedir?

From: Date: Thu, 19 Jun 2014 03:22:41 +0000
Subject: Re: PHP6, drop open_basedir?
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-74980@lists.php.net to get a copy of this message
Hi all, On Thu, Jun 19, 2014 at 7:33 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > On Tue, Jun 17, 2014 at 6:34 PM, Sebastian Krebs <krebs.seb@gmail.com> > wrote: > >> In my experiene it only leads to a false sense of security. I've seen it >> more than once, that people just set a value there and believed, that they >> are now safe. On the other hand they wonder, why many things were broken, >> so they loosen the restrictions again. >> > > I agree that many users do not understand what it does and what it's for. > > It's a fail safe feature that should not be trusted. > open_basedir should not be trusted, but it does not mean > it's useless just like antivirus softwares. Security features > do not have to be perfect to be useful. > > I'm -1 for removing open_basedir. > If there are users who misunderstand what it's for, we > should improve our documentation. IMHO. > BTW, even though I think open_basedir is useful for better security, I also think it's good to encourage users to use better alternatives, selinux, etc. open_basedir is lazy protection, but it's easy to use. Many users disable selinux or like completely. I tends to vote -1 for this, but if there is vote, I would vote 0. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#74980) next »