Re: Re: [RFC][DISCUSSION] script() and script_once()

From: Date: Thu, 05 Feb 2015 10:51:42 +0000
Subject: Re: Re: [RFC][DISCUSSION] script() and script_once()
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-81894@lists.php.net to get a copy of this message
On 5 February 2015 at 10:24, Pierre Joye <pierre.php@gmail.com> wrote: > I do understand what you try to achieve, from all point of view. > However I strongly disagree with this as a security improvement. I see > this more as yet another attempt to replace what should be done at the > OS level. > I'm inclined to agree, this is just another mitigation against a specific vector, not a solution. I'm sure given a little bit of time a way to bypass it will be found. Also introducing this in PHP 7 will not fix all of the currently broken apps, nor will it get people to start using this method even if they do upgrade to PHP 7. I honestly think this is one of the cases where education is better .

« previous php.internals (#81894) next »