Re: [PHP4BETA] PHP 4.0b3 released

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: [PHP4BETA] PHP 4.0b3 released
References: 1  Groups: php.version4 
Request: Send a blank email to php-version4+get-6846@lists.php.net to get a copy of this message
On Tue, 23 Nov 1999 rwidmer@developersdesk.com wrote: > Addressed to: Stanislav Malyshev <stas@zend.com> > php4beta@lists.php.net > > ** Reply to note from Stanislav Malyshev <stas@zend.com> Thu, 18 Nov 1999 15:47:55 +0200 > (IST) > > > In fact, the "root" user notion, as a > > jack-of-all-trades, is rather unsuccessful. You really need no > > superuser access to be able to install a PHP library. And it > > shouldn't be linked to any particular user. > > > > I STRONGLY disagree. The root user is alive and well on every multi > user system I know of, and I don't see it going away any time soon. > Any time someone owns an expensive system and allows others to use it I > expect them to want final say on its operation. I certainly dont want > every email account to be able to install operating system patches, and > I consider the system wide shared PHP library to be almost as > sensitive. > > Imagine the damage if someone 'upgrades' your global phplib so the > database abstraction layer emails everything that looks like a credit > card transaction to them. How do you tell 100 customers that all thier > transactions for the last month have been compromised? I want tight > control over who can update the shared PHP library, and root is the > tightest control I know of on unix. > > I really don't understand what makes you think root user has any tighter control than user foo. The unix model, at least, provides equally tight security irrelevant of who you are...

« previous php.version4 (#6846) next »