Definitely a good idea, as you never know when having the ability to display notices to all users directly in the Manager will come in handy.
I think as far as security update notices they should not be in the main security update feed but as a nag box within the manager interface.
Check out the links right above the download packages here:
Perhaps we should set up a mailing list notification system instead?
php_flag register_globals off
Contrary to popular belief it is not always possible to turn globals off.

I think that windows servers in general may have an issue with register_globals.
) ?I would recommend the opposite direction, a second less imposing warning that globals are on (and any other setting that may be a problem like safe-mode) simply to inform the user that globals are on (in 096 I would put a red/green system checklist bellow the ’icons’ in the welcome page). This way if the website admin, who knows nothing about php, sees the unobtrusive but informative notice they will acknowledge that globals are on (since they see the simple warning on a daily basis) and then when a security notice happens they will identify that they are a potential risk. A single more drastic approach will just be disabled when needed and inform the day-to-day user less rather than more.
Just a thought... should we ship the htaccess with
php_flag register_globals off
We would comment the code like we do for other specific directives, since it can cause problems with host who don’t support it, but add the extra bit about register globals.
# If your server is not already configured as such, the following directive # should be uncommented in order to set PHP's register_globals option to OFF. # This closes a major security hole that is abused by most XSS (cross-site # scripting) attacks. For more information: http://php.net/register_globals # # To verify that this option has been set to OFF, open the Manager and choose # Reports -> System Info and then click the phpinfo() link. Do a Find on Page # for "register_globals". The Local Value should be OFF. If the Master Value # is OFF then you do not need this directive here. # # IF REGISTER_GLOBALS DIRECTIVE CAUSES 500 INTERNAL SERVER ERRORS : # # Your server does not allow PHP directives to be set via .htaccess. In that # case you must make this change in your php.ini file instead. If you are # using a commercial web host, contact the administrators for assistance in # doing this. Not all servers allow local php.ini files, and they should # include all PHP configurations (not just this one), or you will effectively # reset everything to PHP defaults. Consult www.php.net for more detailed # information about setting PHP directives. #php_flag register_globals Off
Contrary to popular belief it is not always possible to turn globals off.I’m still not convinced that this is the case. My understanding is that many hosts leave register_globals set to ON in order to support some old and insecure (but nevertheless popular) software, such as osCommerce. But that doesn’t mean that a particular user couldn’t change this setting for their account using their .htaccess or php.ini file, in which case it would show up as OFF in the local column of their phpInfo() report.