Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security

PHP Security Expert Resigns 386

juct writes "PHP security holes have a name — quite often it was Stefan Esser who found and reported them. Now Esser has quit the PHP security team. He feels that his attempt to make PHP safer "from the inside" is futile. Basic security issues are not addressed sufficiently by the developers. Zeev Suraski, Zend's CTO of course disagrees and urges Stefan to work with the PHP development team instead of working against it. But given the number of remote code execution holes in PHP apps this year, Esser might have a point. And he plans to continue his quest for security holes in PHP. Only that from now on, he will publish them after reasonable time — regardless if a patch is available or not." Update: 10/30 12:57 GMT by KD : Zeev Suraski wrote in to protest: "I'm quoted as if I 'point fingers at inexperienced developers,' and of course, there's no link to that — because it's not true! The two issues — security problems in Web apps written in PHP, and security problems in PHP itself — are two distinct issues. Nobody, including myself, is saying that there are no security problems in PHP — not unlike pretty much any other piece of software. Nobody, I think, argues the fact that there have been many more security problems at the application level, then there were at the language level. I never replied to Stefan's accusations of security problems in PHP saying 'that's bull, it's all the developers' fault,' and I have no intention to do it in the future."
User Journal

Journal Journal: digital archiving

So I've been getting more dvd's recently and I'm starting to have a fairly respectible sci-fi collection. I've had a "wanted" list for some time now, and it keeps getting shorter, but now i'm almost to the point of having to get certain titles that I find to be boring (solaris) just for the sake of completeness. Having a complete archive is important to me, but I'm starting to wonder at what point I need to restrain myself. Another issue I have to start thinking about is the dvd end-of-life s

User Journal

Journal Journal: cycle class

I've enrolled into a motorcycle training class a while ago, and the class is coming up on my schedule soon. I'm excited to learn how to ride bikes without pedals! I'm almost payed up on my Xterra, and I'm starting to shop around for a cheap used motorcycles that I wouldn't mind trashing. Hopefully if everything goes as planned I can be riding my own bike in 3 or 4 months. I want to geek modify the bike as ghetto-akira-fabulous as possible! I will possibly have an integrated 802.11 war-finder,

Slashdot Top Deals

All seems condemned in the long run to approximate a state akin to Gaussian noise. -- James Martin

Working...