Re: [PEAR_DEV] Serializing DB Objects
| From: | Stig S. Bakken | Date: | Wed, 20 Feb 2002 01:16:59 +0000 |
| Subject: | Re: [PEAR_DEV] Serializing DB Objects | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4816@lists.php.net to get a copy of this message | ||
On Tue, 2002-02-19 at 17:21, l0t3k wrote:
> there was a recent thread in this NG about serializing DB objects, and i
> wanted to get an opinion of whether it is safe to do so for connections,
> especially considering that the user name and password would be part of the
> serialized stream, and people sometimes have a habit of storing sessions in
> world readable directories .
>
> or should this be allowed only in safe mode ?
IMHO, the whole safe mode concept is broken, either you do something
like this right, or you don't do it at all. If a programmer does stupid
things like storing credit card numbers somewhere world-readable, the
real problem is way beyond safe mode or PHP.
If you ask me, safe mode does more harm than good because it makes
people think they don't have to worry about application security.
- Stig