Re: Re: Windows Peer Verification

From: Date: Tue, 04 Feb 2014 00:29:29 +0000
Subject: Re: Re: Windows Peer Verification
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi,

On 3 February 2014 23:56, Sanford Whiteman
<[email protected]> wrote:
>> I'm sorry, but this is simply outrageous. It is a programmer's
>> responsibility to code securely. It's not absurd, it's reality. If
>> you can't program securely, you shouldn't be programming.
>
> No, the reality is that (most) PHP users (most of whom are consuming
> someone else's code to some degree) assume that making an SSL
> connection means "secure."
>
> It is absurd to claim otherwise. In fact, _we are agreeing that that
> assumption should always have been correct_ by changing the default
> behavior in PHP!
>
> How can you possibly "blame" users and "fix" the behavior at the same
> time?

Hello. I am a programmer. Sorry, but oopsie, that script I wrote to
retrieve client data from our remote office? Well, I sort of forgot to
configure SSL correctly and, well, somebody dumped a whole list of
client names, emails, social security numbers and other personally
identifiable information onto a file dump site. I'm really really
sorry. It's all PHP's fault.

FIRED! FIRED! FIRED! :P

I blame programmers for security problems because it's their fault.
Anyone who can't take personal responsibility needs to grow up and own
up. Programmers aren't, at least in a professional capacity, children
anymore. This whole attitude of avoiding responsibility by pointing
fingers at anything else is the one thing that drives security people
demented.

>> Your blaming of PHP is significantly misplaced.
>
> No, it is not.

We'll have to agree to disagree about who gets blamed when hackers strike.

> If it were, this patch would not exist, for it has ALWAYS been
> possible to create a peer-verified outbound connection from PHP.
>
> You cannot at once place blame only on the developer and make a core
> change so the language is "the way it should always have been."

You missed the cURL part of my last email, I presume...

--
Pádraic Brady

http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative


Thread (53 messages)

« previous php.internals (#72161) next »