Re: PHP6, drop open_basedir?
| From: | Yasuo Ohgaki | Date: | Thu, 19 Jun 2014 03:22:41 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74980@lists.php.net to get a copy of this message | ||
Hi all,
On Thu, Jun 19, 2014 at 7:33 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> On Tue, Jun 17, 2014 at 6:34 PM, Sebastian Krebs <krebs.seb@gmail.com>
> wrote:
>
>> In my experiene it only leads to a false sense of security. I've seen it
>> more than once, that people just set a value there and believed, that they
>> are now safe. On the other hand they wonder, why many things were broken,
>> so they loosen the restrictions again.
>>
>
> I agree that many users do not understand what it does and what it's for.
>
> It's a fail safe feature that should not be trusted.
> open_basedir should not be trusted, but it does not mean
> it's useless just like antivirus softwares. Security features
> do not have to be perfect to be useful.
>
> I'm -1 for removing open_basedir.
> If there are users who misunderstand what it's for, we
> should improve our documentation. IMHO.
>
BTW, even though I think open_basedir is useful for better security,
I also think it's good to encourage users to use better alternatives,
selinux, etc. open_basedir is lazy protection, but it's easy to use.
Many users disable selinux or like completely.
I tends to vote -1 for this, but if there is vote, I would vote 0.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net