Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Do you whitelist or blacklist utf-8?
- Date: Fri, 25 Feb 2011 08:52:07 +0900
- From: Darren Cook <darren@example.com>
- Subject: Re: [tlug] Do you whitelist or blacklist utf-8?
- References: <4D639689.1010302@example.com> <4D63EFBC.1020900@example.com> <4D64C5DD.1040607@example.com> <4D64CB49.10906@example.com> <4D652AF5.10304@example.com> <4D655712.1090608@example.com> <37687.61.213.3.170.1298510044.squirrel@example.com> <4D661A15.8010009@example.com> <4D666540.5000705@example.com>
- User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.13) Gecko/20101208 Thunderbird/3.1.7
> You've probably already seen the other replies, but the > number of PHP vulnerabilities was overwhelming a few years back. I've not see any reply yet to tell me that a recent release of PHP is "insecure". Josh's googits can just as easily be interpreted as "more eyeballs looking at PHP mean more of the bugs are fixed". What would make me sit up and pay attention is if you showed me that a php 5.2.x or 5.3.x release was released with serious security bugs in the core (as opposed to in some new specialist library that has just been added). As far as I know most of PHP's bad security reputation is due to bad practices in frameworks and software built with PHP, and mostly before attacks such as XSS has even been invented. But I know the reputation annoys the core developers, so they have been very security conscious in releases in the past few years; a bit like a female doctor in a male-dominated hospital who feels she has to work harder than everyone else to prove herself. The very big websites using PHP, such as Facebook and Wikipedia, never complain about PHP not being secure enough. When giving the pros and cons, the only con I see given is: "PHP isn't as fast as C" [1]. Darren [1]: See https://github.com/facebook/hiphop-php/wiki/ for one way Facebook deal with this. -- Darren Cook, Software Researcher/Developer http://dcook.org/work/ (About me and my work) http://dcook.org/blogs.html (My blogs and articles)
- Follow-Ups:
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Edmund Edgar
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Stephen J. Turnbull
- References:
- [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Nikolay Elenkov
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Darren Cook
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Nikolay Elenkov
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] I'll have to pay someone to do this Javascript (small job offer)
- Next by Date: Re: [tlug] Do you whitelist or blacklist utf-8?
- Previous by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links