Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!gegeweb.org!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Wed, 11 Jan 2012 18:09:22 +0100 Organization: A noiseless patient Spider Lines: 47 Message-ID: <4F0DC242.6040502@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> <4F09F3F2.50108@arnowelzel.de> <4F0D5DBD.4050404@arnowelzel.de> <4F0DA104.6060501@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="dd4uQGf4fHOQcq7/hg1u1Q"; logging-data="15734"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18kujBh7Zp5qnOyEhauvACUupTmaUfE5qY=" User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20111105 Thunderbird/8.0 In-Reply-To: Cancel-Lock: sha1:JtxQpU/5lqD1uHIlGD2yly8rQj4= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4425 Jerry Stuckle, 2012-01-11 15:51: > On 1/11/2012 9:47 AM, Arno Welzel wrote: >> Jerry Stuckle, 2012-01-11 14:44: >> >>> On 1/11/2012 5:00 AM, Arno Welzel wrote: >>>> Jerry Stuckle, 2012-01-08 21:59: >>>> >>>> [...] >>>>> I do other things also, but don't want to get into too much detail in a >>>>> public forum. >>>> >>>> "Security by obscurity" does not work. If your security only relies on >>>> the fact, that you try to keep the procedures or code a secret, it is >>>> flawed. >>> >>> No, security by obscurity does not work. But that does not mean one >>> should broadcast to the world everything he does. >> >> Of course it is not neccessary to publish every detail about the >> procedures to avoid spam, attacks etc. - but some basic procedures >> should be discussed in public, since you might often think you are >> "secure" but you just didn't see the flaws in your procedures yet. >> >> For example: I use SpamAssassin and do greylisting on my server. If i >> would get less spam just because i keep this information a secret then >> SpamAssassin itself and greylistign should be considered useless. >> >> > > In your opinion, anyway. Security experts (which I don't claim to be - > but know several) disagree. There is no reason to draw a map to your > house even if the door is locked. Well - usually you don't need to draw a map to a house, since maps of most areas in the world already exist. Did you mean "no reason to publish the address of a house..."? But where does this end... "no reason to do let anyone even know you exist at all?" *scnr* Concerning PHP: Code is not more secure, just because it is closed source. I don't think, that any security expert will tell the opposite. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de