Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:33332 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 51586 invoked by uid 1010); 19 Nov 2007 20:50:31 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 51569 invoked from network); 19 Nov 2007 20:50:31 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 19 Nov 2007 20:50:31 -0000 Authentication-Results: pb1.pair.com smtp.mail=dz@bitxtender.com; spf=permerror; sender-id=unknown Authentication-Results: pb1.pair.com header.from=dz@bitxtender.com; sender-id=unknown Received-SPF: error (pb1.pair.com: domain bitxtender.com from 80.237.132.12 cause and error) X-PHP-List-Original-Sender: dz@bitxtender.com X-Host-Fingerprint: 80.237.132.12 wp005.webpack.hosteurope.de Received: from [80.237.132.12] ([80.237.132.12:56789] helo=wp005.webpack.hosteurope.de) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 95/00-50425-907F1474 for ; Mon, 19 Nov 2007 15:50:18 -0500 Received: from dslb-084-056-021-028.pools.arcor-ip.net ([84.56.21.28] helo=localhost); authenticated by wp005.webpack.hosteurope.de running ExIM using esmtpsa (TLSv1:RC4-SHA:128) id 1IuDZN-0007G7-NI; Mon, 19 Nov 2007 21:50:13 +0100 Cc: Stefan Esser , Dan Scott , Stefan Esser , PHP internals Message-ID: <21E0FBBA-645D-4883-A9A9-7BCDC74D74A1@bitxtender.com> To: Lukas Kahwe Smith In-Reply-To: <4217C4AB-1725-4D54-95D0-82262DB012BC@pooteeweet.org> Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit Mime-Version: 1.0 (Apple Message framework v915) Date: Mon, 19 Nov 2007 21:50:12 +0100 References: <47401946.2050406@sektioneins.de> <4740B136.2080207@hardened-php.net> <4217C4AB-1725-4D54-95D0-82262DB012BC@pooteeweet.org> X-Mailer: Apple Mail (2.915) X-bounce-key: webpack.hosteurope.de;dz@bitxtender.com;1195505418;8a95dfaf; Subject: Re: [PHP-DEV] Tainted Mode Decision From: dz@bitxtender.com (=?ISO-8859-1?Q?David_Z=FClke?=) Am 18.11.2007 um 22:53 schrieb Lukas Kahwe Smith: > Stefan so what is your point then? Since neither can be 100% secure, > do not use any? Or just do not bundle either? Yes, that is exactly the way to go. To quote Yoda (and he would know): "Do, or do not. There is no try.". Or, in contemporary words: do things 100% properly, but if that is not possible, take a step back and spare the world some half arsed attempt. David