Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Note: You can take 10% off all Slashdot Deals with coupon code "slashdot10off." ×
PHP

Submission + - Is PHP Insecure?->

darthcamaro writes: Over 60 bugs were reported in PHP over the last 30 days, should PHP users and developers be worried? Most of the flaws however are ones that developers themselves can protect against with proper coding practices according to the Andi Gutmans CEO of commercial PHP vendor Zend. He argues that PHP security is a matter of setting expectations. In his view, PHP — like all development languages, is only as secure as the code people that write code with it.

"People should not expect PHP to be able to enforce security boundaries on a developer that has permissions to run custom PHP code," Gutmans said. "It's an inherently flawed scenario — and it's the wrong layer to protect in. People must rely on properly-configured OS-level permissions for securing against untrusted developers."


Link to Original Source
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Is PHP Insecure?

Comments Filter:

"The fundamental principle of science, the definition almost, is this: the sole test of the validity of any idea is experiment." -- Richard P. Feynman

Working...