Re: [PHP4BETA] PHP 4.0b3 released
| From: | Joey Smith | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: [PHP4BETA] PHP 4.0b3 released | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-6846@lists.php.net to get a copy of this message | ||
On Tue, 23 Nov 1999 rwidmer@developersdesk.com wrote:
> Addressed to: Stanislav Malyshev <stas@zend.com>
> php4beta@lists.php.net
>
> ** Reply to note from Stanislav Malyshev <stas@zend.com> Thu, 18 Nov 1999 15:47:55 +0200
> (IST)
>
> > In fact, the "root" user notion, as a
> > jack-of-all-trades, is rather unsuccessful. You really need no
> > superuser access to be able to install a PHP library. And it
> > shouldn't be linked to any particular user.
> >
>
> I STRONGLY disagree. The root user is alive and well on every multi
> user system I know of, and I don't see it going away any time soon.
> Any time someone owns an expensive system and allows others to use it I
> expect them to want final say on its operation. I certainly dont want
> every email account to be able to install operating system patches, and
> I consider the system wide shared PHP library to be almost as
> sensitive.
>
> Imagine the damage if someone 'upgrades' your global phplib so the
> database abstraction layer emails everything that looks like a credit
> card transaction to them. How do you tell 100 customers that all thier
> transactions for the last month have been compromised? I want tight
> control over who can update the shared PHP library, and root is the
> tightest control I know of on unix.
>
>
I really don't understand what makes you think root user has any tighter
control than user foo. The unix model, at least, provides equally tight
security irrelevant of who you are...