Stefan Esser, PHP security specialist and member of the official PHP Security Response Team has, he says, had enough - in his blog he has announced his immediate resignation from the PHP Security Response Team. He states that he has various reasons for doing so, the most important of which is that his attempt to make PHP safer "from the inside" is futile. According to Esser, as soon as you try to criticise PHP security, you become persona-non-grata in the security team. In addition many of his suggestions were ignored because the developers considered Esser's choice of words, too abrasive. He says that he had stopped counting the number of times he was called a traitor when he published a bug report on a vulnerability in PHP.
According to Esser, he is going to drastically up the number of security advisories for PHP. Some of them will come without fixes. PHP site administrators are going to need to be on their toes. PHP has more than it's fair share of security problems.. Problems caused by the language, users, and ubiquity. The slant of all the articles I've seen on it suggests there is a see no evil, hear no evil, speak no evil approach being taken. heise Security - News - Security specialist leaves PHP security team |