Re: [PEAR_DEV] Serializing DB Objects

From: Date: Wed, 20 Feb 2002 01:16:59 +0000
Subject: Re: [PEAR_DEV] Serializing DB Objects
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4816@lists.php.net to get a copy of this message
On Tue, 2002-02-19 at 17:21, l0t3k wrote: > there was a recent thread in this NG about serializing DB objects, and i > wanted to get an opinion of whether it is safe to do so for connections, > especially considering that the user name and password would be part of the > serialized stream, and people sometimes have a habit of storing sessions in > world readable directories . > > or should this be allowed only in safe mode ? IMHO, the whole safe mode concept is broken, either you do something like this right, or you don't do it at all. If a programmer does stupid things like storing credit card numbers somewhere world-readable, the real problem is way beyond safe mode or PHP. If you ask me, safe mode does more harm than good because it makes people think they don't have to worry about application security. - Stig

« previous php.pear.dev (#4816) next »