From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([69.77.167.62] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1JHT2Q-0005Qp-T4 for garchives@archives.gentoo.org; Wed, 23 Jan 2008 00:00:19 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 12BFDE07CE; Wed, 23 Jan 2008 00:00:17 +0000 (UTC) Received: from ug-out-1314.google.com (ug-out-1314.google.com [66.249.92.174]) by pigeon.gentoo.org (Postfix) with ESMTP id C2ADBE07CE for ; Wed, 23 Jan 2008 00:00:16 +0000 (UTC) Received: by ug-out-1314.google.com with SMTP id j3so19338ugf.49 for ; Tue, 22 Jan 2008 16:00:16 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; bh=gn4e9fn6CpkClvigXO2MyPhHxompxXCrJ4xYd7m7QqU=; b=QEayKgM89VXCgVyU7v15gizsJtIm3TcBzytatw3QiVuy21yiSOp1eP286rahYWJGJvnUAi9S4hwBZ5BEnYohcz2bJASqkUK14WhFQpqS5BmIeSoGFUOHjkjPUbJ32h8At1VBS+ePEu8ShryFSyba6ESE+SGPWcbOvGHMacTWWEE= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:user-agent:mime-version:to:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; b=lwHpfwXi5RJIrmn8AE/7viMcgTsSjCYISZWFOI1f+JWG8WcvSFRBzaMxs3XT/TXsgWi8Fy3FCQtaEVw/Pw1iLiNYGkPTqb93CZNRQsijXQKNyN/odIIwd6BBGbfd68axWdtR7qYZU4KDF30+KcF+1BQSkhp8/PnTL8nLG2vSptU= Received: by 10.67.122.12 with SMTP id z12mr239717ugm.18.1201046415827; Tue, 22 Jan 2008 16:00:15 -0800 (PST) Received: from ?80.77.252.126? ( [80.77.252.126]) by mx.google.com with ESMTPS id x6sm9154257gvf.0.2008.01.22.16.00.14 (version=TLSv1/SSLv3 cipher=RC4-MD5); Tue, 22 Jan 2008 16:00:15 -0800 (PST) Message-ID: <47968389.4010800@gmail.com> Date: Wed, 23 Jan 2008 00:00:09 +0000 From: Qian Qiao User-Agent: Thunderbird 2.0.0.9 (X11/20080111) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-server@lists.gentoo.org Reply-to: gentoo-server@lists.gentoo.org MIME-Version: 1.0 To: gentoo-server@lists.gentoo.org Subject: Re: [gentoo-server] PHP4 References: <20080118110850.C41241@shell.bway.net> <47961632.5000000@foobar.lu> <479617AD.3040800@gentoo.org> <1201025554.5987.27.camel@localhost.localdomain> <4796382F.1060001@foobar.lu> <1201029004.7553.10.camel@localhost.localdomain> <47968008.10105@foobar.lu> In-Reply-To: <47968008.10105@foobar.lu> X-Enigmail-Version: 0.95.5 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Archives-Salt: 895cc47c-a911-4271-8ebf-629a764caaee X-Archives-Hash: 3765a09b22fea55c5839737dfd1fb06c -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yves Thommes wrote: > finally it's our responsibility to keep the sites running and > secure PHP4 doesn't just pose security threat to a particular web app, but the machine or even the cluster it runs on, one buggy php4 version or php4 application can potentially take down the entire cluster. As I've said before, if they insist on running PHP4, then the only logical solution will be to run PHP4 on it's own cluster, so when it's hacked, the damage is contained. If the additional cost of such a solution cannot be covered by the customers insist on running PHP4, then the responsible solution is to drop support of PHP4, in interest of other customers who do want to go for the more secure solution, they should not be punished by those who insist on staying php4. - -- Joe - -- A computer scientist is someone who, when told "go to hell", considers the "go to" harmful rather than the destination. GnuPG Key: 0xB14661D9 GnuPG FP: DE08 57AE A1AD 620C 02AA CCDD 611B 63AC B146 61D9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) iD8DBQFHloOJYRtjrLFGYdkRAgJVAJkBCjvbrXzry69xMmL1rKl19NNqUgCg1gph sOWQEniwflNLyEzVpABPWrs= =SiWm -----END PGP SIGNATURE----- -- gentoo-server@lists.gentoo.org mailing list