<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Sun, 26 May 2013 02:19:26 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Zeev Suraski's Blog: PHP Security]]></title>
      <guid>http://www.phpdeveloper.org/news/6900</guid>
      <link>http://www.phpdeveloper.org/news/6900</link>
      <description><![CDATA[<p>
To set things right about a <a href="http://it.slashdot.org/it/06/12/14/0410240.shtml">misquote on Slashdot</a>, <i>Zeev Suraksi</i> has posted <a href="http://suraski.net/blog/index.php?/archives/17-PHP-Security.html">this long statement</a> mentioning what he really said and a few more personal opinions.
</p>
<blockquote>
I've just been <a href="http://it.slashdot.org/it/06/12/14/0410240.shtml">misquoted on Slashdot</a>, as if I said there are no security problems in PHP itself, and that I instead point my finger only at inexperienced developers. If you read the original article on <a href="http://www.heise-security.co.uk/news/82500">Heise Security</a>, you'll see that I have not said anything of the sort. [...] I believe this is the belief of most others on the security team, but I'm only speaking on behalf of myself and do not represent them.
</blockquote>
<p>
He <a href="http://suraski.net/blog/index.php?/archives/17-PHP-Security.html">also covers</a> five more points pertaining to the article and the situation:
<ul>
<li>Where the bugs/problems lie with problems in PHP
<li>Why there are security problems in web PHP applications
<li>Why the current security level can be partially blamed on the language itself
<li>An admission that yes, there are security problems in PHP
<li>And the track record the PHP developers have had in fixing these issues
</ul>
There's much more than just these brief highlights here, so I encourage you to <a href="http://suraski.net/blog/index.php?/archives/17-PHP-Security.html">head on over</a> and check out the full post for yourself.
</p>
<p>
There are some other opinions on the matter from a few others out there too:
<ul>
<li><a href="http://www.cyberlot.net/phpisitinsecure">cyberlot's blog</a>
<li><a href="http://devzone.zend.com/node/view/id/1370">Zend Developer Zone's post</a>
<li><a href="http://www.tonybibbs.com/article.php/NotAgain">Tony Bibbs' blog</a>
</ul>
</p>]]></description>
      <pubDate>Thu, 14 Dec 2006 15:36:38 -0600</pubDate>
    </item>
  </channel>
</rss>
