Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Of course, giving your php webapp the permission to rewrite it's core files is a brilliant and secure idea!


Most operating systems do it. It's not an intractable problem.


Said operating systems typically require you to use an account that is inaccessible to almost all automated processes. This would not be the case, the two are not analogous.


Signed binary's can get you most of the way there. It's still a trade-off and for most users waiting to apply a security patch is a larger danger.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: