Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!gegeweb.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Wed, 11 Jan 2012 15:43:34 +0100 Organization: A noiseless patient Spider Lines: 48 Message-ID: <4F0DA016.9030503@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> <4F09F3F2.50108@arnowelzel.de> <4F0D5DBD.4050404@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dd4uQGf4fHOQcq7/hg1u1Q"; logging-data="27385"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18SwKQ34YPAnUFLiEMzNGJHCaZcAct3t5g=" User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: Cancel-Lock: sha1:G6r0kNfpqhQF5k6NS1/hXIyNXas= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4421 The Natural Philosopher, 2012-01-11 12:53: > Arno Welzel wrote: >> Jerry Stuckle, 2012-01-08 21:59: >> >> [...] >>> I do other things also, but don't want to get into too much detail in a >>> public forum. >> >> "Security by obscurity" does not work. > > actually it does. It is the basis for all passwords for example. I did'nt talk about passwords m( but *procedures*. And a secret password is not "security by obscurity". In cryptography this is the most important principle: Keep the password or private key as a secret but not the procedure - and cryptographic procedures which are not documented have to be considered insecure. If you say "i do something in my application to keep it secure, but i won't tell anybody what this is - because if i would, a hacker could use this information to attack my application" - then your procedure is flawed, since you risk that the whole thing may fail as soon as someone find's out, how it works. I procedure has to be secure *even* when everybody knows how it works. For example: A packet filter in Linux is also not secure because nobody knows how it works. Or another example: A user database must never store plain text passwords but only in an encrypted form - but the procedure of the encryption must be documented. Otherwise you never will know, if there are flaws in the procedure which are already used by attackers. And if you are not an expert in cryptography don't even think about creating your own "secure" encryption - and the same often also applies to code which is considered to be "secure" against attacks. > If your security only relies on >> the fact, that you try to keep the procedures or code a secret, it is >> flawed. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de