<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PHP Security: Dumb Users or Dumb APIs?</title>
	<atom:link href="http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<lastBuildDate>Sun, 22 Nov 2009 11:54:05 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: crfzorgmzx</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-161837</link>
		<dc:creator>crfzorgmzx</dc:creator>
		<pubDate>Wed, 24 Jan 2007 09:30:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-161837</guid>
		<description>&lt;a href=&quot;http://ednlybbmphd.com&quot; rel=&quot;nofollow&quot;&gt;yydeix&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://ednlybbmphd.com" rel="nofollow">yydeix</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: planderman</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-153435</link>
		<dc:creator>planderman</dc:creator>
		<pubDate>Sat, 13 Jan 2007 21:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-153435</guid>
		<description>It seems like there&#039;s a lot of php security risks when it comes to accepting input from a Web site or displaying data on a Web site. I doubt there&#039;s any way to prevent them all, but is there a way to stop the top threats, maybe the top 5 threats?</description>
		<content:encoded><![CDATA[<p>It seems like there&#8217;s a lot of php security risks when it comes to accepting input from a Web site or displaying data on a Web site. I doubt there&#8217;s any way to prevent them all, but is there a way to stop the top threats, maybe the top 5 threats?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Hl4bFeK6tO</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-35419</link>
		<dc:creator>Hl4bFeK6tO</dc:creator>
		<pubDate>Thu, 06 Jul 2006 02:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-35419</guid>
		<description>uQtIgOAlE6KM qEgJ1S3mhQ B3o6TVDytknP15</description>
		<content:encoded><![CDATA[<p>uQtIgOAlE6KM qEgJ1S3mhQ B3o6TVDytknP15</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Icheb</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13246</link>
		<dc:creator>Icheb</dc:creator>
		<pubDate>Sat, 28 Jan 2006 04:56:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13246</guid>
		<description>&lt;blockquote&gt;So what’s you’re point sir?&lt;/blockquote&gt;
My eyes hurt after having to read that sentence.</description>
		<content:encoded><![CDATA[<blockquote><p>So what’s you’re point sir?</p></blockquote>
<p>My eyes hurt after having to read that sentence.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: RodeWorks &#187; PHP Security</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13206</link>
		<dc:creator>RodeWorks &#187; PHP Security</dc:creator>
		<pubDate>Fri, 27 Jan 2006 18:26:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13206</guid>
		<description>[...] SitePoint Blogs » PHP Security: Dumb Users or Dumb APIs? [...]</description>
		<content:encoded><![CDATA[<p>[...] SitePoint Blogs » PHP Security: Dumb Users or Dumb APIs? [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: WebDevGuy</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13200</link>
		<dc:creator>WebDevGuy</dc:creator>
		<pubDate>Fri, 27 Jan 2006 14:34:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13200</guid>
		<description>

&lt;blockquote&gt;If people don’t take the time to learn the correct way to do something, ...&lt;/blockquote&gt;


The problem with that is where do you go to learn?  One expert might do it this way and another expert another way.

This is what I meant when I said earlier that until there is one recognized authority, it will be every man for himself.

I am NOT advocating everyone give up their freedom and I am not saying we have to have a more secure base PHP be default.

What I am saying is that everyone needs to educate themselves but in a standard way from an authoritative source.  That source would consist of of 8 - 10 experts agreeing on a common way to overcome security isses.

You might laugh and say, we can&#039;t get 8 - 10 people to agree on that.  If you do...you have restated the problem I am raising.</description>
		<content:encoded><![CDATA[<blockquote><p>If people don’t take the time to learn the correct way to do something, &#8230;</p></blockquote>
<p>The problem with that is where do you go to learn?  One expert might do it this way and another expert another way.</p>
<p>This is what I meant when I said earlier that until there is one recognized authority, it will be every man for himself.</p>
<p>I am NOT advocating everyone give up their freedom and I am not saying we have to have a more secure base PHP be default.</p>
<p>What I am saying is that everyone needs to educate themselves but in a standard way from an authoritative source.  That source would consist of of 8 &#8211; 10 experts agreeing on a common way to overcome security isses.</p>
<p>You might laugh and say, we can&#8217;t get 8 &#8211; 10 people to agree on that.  If you do&#8230;you have restated the problem I am raising.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Techniek &#187; Projecten PHP en beveiliging</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13180</link>
		<dc:creator>Techniek &#187; Projecten PHP en beveiliging</dc:creator>
		<pubDate>Fri, 27 Jan 2006 08:24:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13180</guid>
		<description>[...] PHP is echter van nature niet zo veilig. Als je niet uitkijkt hoe je programmeert krijg je te maken allerlei ongein zoals Cross Site Scripting attacks (XSS), Session hijacking en vooral ook SQL injection. [...]</description>
		<content:encoded><![CDATA[<p>[...] PHP is echter van nature niet zo veilig. Als je niet uitkijkt hoe je programmeert krijg je te maken allerlei ongein zoals Cross Site Scripting attacks (XSS), Session hijacking en vooral ook SQL injection. [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: malikyte</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13165</link>
		<dc:creator>malikyte</dc:creator>
		<pubDate>Thu, 26 Jan 2006 20:31:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13165</guid>
		<description>Nick, the unfortunate thing is that it still comes back to PHP itself.  With your dynamite example:

1.) You can try to make some dynamite from scratch, buying all the chemicals, mixing it all together, pouring it into the candles...

...OR...

2.) You buy a kit with simple instructions and safety precautions.

#2 doesn&#039;t necessarily mean that it&#039;s never going to be unsafe, but it&#039;s a better chance that you&#039;d have less problems because you don&#039;t have to worry about the deep down nitty gritty stuff.  This is something like PHP (#1) and ASP.NET (#2).

Personally, I prefer PHP over ASP.NET (using C#), but that&#039;s just me.</description>
		<content:encoded><![CDATA[<p>Nick, the unfortunate thing is that it still comes back to PHP itself.  With your dynamite example:</p>
<p>1.) You can try to make some dynamite from scratch, buying all the chemicals, mixing it all together, pouring it into the candles&#8230;</p>
<p>&#8230;OR&#8230;</p>
<p>2.) You buy a kit with simple instructions and safety precautions.</p>
<p>#2 doesn&#8217;t necessarily mean that it&#8217;s never going to be unsafe, but it&#8217;s a better chance that you&#8217;d have less problems because you don&#8217;t have to worry about the deep down nitty gritty stuff.  This is something like PHP (#1) and ASP.NET (#2).</p>
<p>Personally, I prefer PHP over ASP.NET (using C#), but that&#8217;s just me.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13161</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Thu, 26 Jan 2006 16:50:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13161</guid>
		<description>Screw the newbies. If you read a book on dynamite, then go out and try to make some, you are a fool (likely a a dead or deformed fool at this point). Same logic applies here IMHO. If people don&#039;t take the time to learn the correct way to do something, they have no one to blame but themselves for the eventual repercussions. This is not a discussion about the security (or lack thereof) in PHP, but rather human nature in general. Just my $0.02.</description>
		<content:encoded><![CDATA[<p>Screw the newbies. If you read a book on dynamite, then go out and try to make some, you are a fool (likely a a dead or deformed fool at this point). Same logic applies here IMHO. If people don&#8217;t take the time to learn the correct way to do something, they have no one to blame but themselves for the eventual repercussions. This is not a discussion about the security (or lack thereof) in PHP, but rather human nature in general. Just my $0.02.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Cyberborean Chronicles &#187; Blog Archive &#187; [Links:] Jan, 26 2006</title>
		<link>http://www.sitepoint.com/blogs/2006/01/24/php-security-dumb-users-or-dumb-apis/comment-page-1/#comment-13149</link>
		<dc:creator>Cyberborean Chronicles &#187; Blog Archive &#187; [Links:] Jan, 26 2006</dc:creator>
		<pubDate>Thu, 26 Jan 2006 07:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.sitepoint.com/blogs/?p=1387#comment-13149</guid>
		<description>[...] Sitepoint blogs: PHP Security: Dumb Users or Dumb APIs? [...]</description>
		<content:encoded><![CDATA[<p>[...] Sitepoint blogs: PHP Security: Dumb Users or Dumb APIs? [...]</p>]]></content:encoded>
	</item>
</channel>
</rss>
