Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!eternal-september.org!feeder.eternal-september.org!mx04.eternal-september.org!.POSTED!not-for-mail From: Arno Welzel Newsgroups: comp.lang.php Subject: Re: Magic quotes? Should I still be cautious? Date: Thu, 12 Jan 2012 08:58:40 +0100 Organization: A noiseless patient Spider Lines: 40 Message-ID: <4F0E92B0.9030808@arnowelzel.de> References: <4F046877.3080409@arnowelzel.de> <4f05a0b4$0$6924$e4fe514c@news2.news.xs4all.nl> <9mmq09F283U1@mid.uni-berlin.de> <4F09F3F2.50108@arnowelzel.de> <4F0D5DBD.4050404@arnowelzel.de> <4F0DA104.6060501@arnowelzel.de> <4F0DC242.6040502@arnowelzel.de> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Injection-Info: mx04.eternal-september.org; posting-host="LDQEG7JhwNN4wgf9ro7Ddg"; logging-data="25305"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/8wf1/Xpm+T+NooGraGr11tAPr4BQLprE=" User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0) Gecko/20111222 Thunderbird/9.0.1 In-Reply-To: Cancel-Lock: sha1:EhylRC8VW4Ym/bDIjIgqVejPBW0= Xref: x330-a1.tempe.blueboxinc.net comp.lang.php:4432 Jerry Stuckle, 2012-01-11 20:01: > On 1/11/2012 12:09 PM, Arno Welzel wrote: [...] >> Concerning PHP: Code is not more secure, just because it is closed >> source. I don't think, that any security expert will tell the opposite. >> > > Let's see you find detailed instructions on how to build a hydrogen > bomb. You won't find it - it's secret. Never mind that you could never > do it because you don't have a source of highly enriched uranium or > plutonium required for the trigger. > > Not telling the world how you do something is not "security by > obfuscation". But it IS security. > > And once again, this is off topic in this newsgroup and will be the last > I have to say about the subject. Sorry - but *you* mentioned off-topic examples for "security" twice which have nothing to do with the topic of *PHP*. I never talked about houses, bombs etc. - just security in *software*. You claimed, security experts say, closed source is good for security. If this statement was not about *software*, then your first statement was already off-topic. To get back to the topic: Magic Quotes was also an attempt to make PHP scripts more secure by avoiding SQL injection. Unfortunately in the early days of PHP the people behind PHP seemed to know little about security and PHP was never meant as a powerful universal language for web applications. Now we have still to deal with many of those historical attempts to be "secure" like safe mode, Magic Quotes etc. - but you must be aware, that PHP is not secure by design. -- Arno Welzel http://arnowelzel.de http://de-rec-fahrrad.de