-
MODX Staff
- 2,502 Posts
It should be said that you only need php.ini files in the manager folders and your install root and anywhere you have snippet files such as assets/snippets/*
On a related note I gave my host a hard time about compiling php with register globals set to on and to my surprise they don’t do it anymore. HostGator have a decent reputation. I would think that (I can’t see why) they would leave register globals on for convenience but run suexec to handle and prevent XSS if they want to curb XSS attacks on a shared server they should follow PHPs recommended deployment and have it off.
Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup
magician.
Blog ✦
Twitter ✦
LinkedIn ✦
GitHub
What is the convenience? I would think it is a critical mass thing, no? What would a host gain in having this on?
On a side note: this is the first time I have ever called the hostgator tech support line. I was really impressed that I was speaking to a knowledgeable person in like 10 seconds! On a Saturday evening no less. This will be my third hostgator site and so far I have no negative issues...
-
☆ A M B ☆
- 24,524 Posts
There are some badly written apps that won’t work if it’s not on. So they get complaints from people who want to use those scripts if they turn it off, and complaints from the rest of us if it’s on. Eventually those scripts will go away, since the option has been removed entirely as of PHP 6.
Susan, so what you are saying is the host is supporting the lowest common denominator? Sort of like us designers who have to build sites that support IE 6???
-
☆ A M B ☆
- 24,524 Posts
-
MODX Staff
- 2,502 Posts
I know why they did it in the beginning and it was because most hosts didn’t know that XSS on the register_globals vector was going to be bad. If you know people who become hosts, they are usually far less knowledgeable than the people writing the scripts.
Sure hosts will not have a choice when PHP6 comes out but many shared host are just now adopting PHP5 but they are having to tighten security because servers that keep getting exploited go down and cost money so it will become too expensive to have loose PHP configurations. The fact that most shared hosts are moving to suExec indicates that they are getting worried.
Honestly this is not a comparison to legacy IE because if IE 5 was as insecure as some loose PHP confs Microsoft would have forced corporate clients to upgrade.
I think now most are finding that we’ll disable and see who complains and then tell them to fix it. If you are running mission critical apps on shared hosting you deserve to have your insecure app break.
Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup
magician.
Blog ✦
Twitter ✦
LinkedIn ✦
GitHub
-
☆ A M B ☆
- 24,524 Posts
Also Microsoft has never been held responsible for their insecure crap, since most people don’t understand the problem nor do they know they have a choice; while a hosting company with a bad security record will get hit in the pocketbook as people abandon them.
-
MODX Staff
- 2,502 Posts
True!
Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup
magician.
Blog ✦
Twitter ✦
LinkedIn ✦
GitHub