Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Do you whitelist or blacklist utf-8?
- Date: Sun, 27 Feb 2011 09:33:24 +0900
- From: Darren Cook <darren@example.com>
- Subject: Re: [tlug] Do you whitelist or blacklist utf-8?
- References: <4D639689.1010302@example.com> <4D63EFBC.1020900@example.com> <4D64C5DD.1040607@example.com> <4D64CB49.10906@example.com> <4D652AF5.10304@example.com> <4D655712.1090608@example.com> <37687.61.213.3.170.1298510044.squirrel@example.com> <4D661A15.8010009@example.com> <4D666540.5000705@example.com> <4D66EF27.7070905@example.com> <87sjvcd49n.fsf@example.com>
- User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.13) Gecko/20101208 Thunderbird/3.1.7
> > What would make me sit up and pay attention is if you showed me that a > > php 5.2.x or 5.3.x release was released with serious security bugs in > > the core (as opposed to in some new specialist library that has just > > been added). > > That's an unreasonable condition in a project whose popularity derives > significantly from rapid assimilation of "new specialist libraries". This side thread started because I thought the original comment ("And, yeah, for better security, don't use PHP") sounded unreasonable. From what I've learnt in this thread it seems the original comment should have read: "And, yeah, for better security don't use a version of PHP more than 5 years old, and don't use frameworks or other libraries (with any language) unless you are sure the authors understand the various security attacks." Sorry for the pedanticism, I realize that version isn't so catchy :-) Darren P.S. I hate language wars, even when I'm joining in them. But it matters out there in the Real World: for many web projects there will be a PHP Quote, and a Java Quote, and typically the features and prices and schedule will be comparable. In truth the security, reliability and speed of the underlying languages are also comparable (meaning equivalent enough that it won't matter for the success of the project), and what the decision maker should be doing is comparing the likelihood of each development team being able to do what they say they can. It is just very annoying when the inferior team is chosen because of something the decision maker heard in a bar from a language advocate. :-) -- Darren Cook, Software Researcher/Developer http://dcook.org/work/ (About me and my work) http://dcook.org/blogs.html (My blogs and articles)
- Follow-Ups:
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Raymond Wan
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Josh Glover
- References:
- [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Dave M G
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Shmuel Fomberg
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Nikolay Elenkov
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Darren Cook
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Nikolay Elenkov
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Darren Cook
- Re: [tlug] Do you whitelist or blacklist utf-8?
- From: Stephen J. Turnbull
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] [Javascript] enabling/disabling buttons: enter key
- Next by Date: Re: [tlug] Do you whitelist or blacklist utf-8?
- Previous by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Next by thread: Re: [tlug] Do you whitelist or blacklist utf-8?
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links