hi Stefan, On Sat, Feb 4, 2012 at 9:41 AM, Stefan Esser <ste...@nopiracy.de> wrote:
> But instead of accepting the gift, people like Pierre run around and tell > everybody that people only have more problems due to Suhosin, that he is > happy that it gets dropped, bla bla bla. Yes, it causes more issues that it solves in the long run. That's my experiences and the same has been told by other people. There is no personal reason behind it, but pure technical experiences. > This is ironic because Pierre's employer is Microsoft (excuse me if that is > not correct anymore). Again you are totally wrong. I work with them not for. And can you please once in this thread (or at all) stop your kiddish personal attack and finally bring technical points to this discussion? Can you do it? > Microsoft created "recently" Suhosin for Windows. They call it EMET and they > actively support it, not fight it like cancer. It is a very pretentious to consider that EMET has been created from or because of Suhosin. Also some Suhosin features are per se enabled on Windows through VC options (whehter they act the same way or not is disputable but you know it). > I see NO REASON why I should kill Suhosin and maybe 5 of 100 > features/mitigations go into mainline PHP. > If that happens it is not good enough for me. I want all 100 > features/mitigations in MY SERVERS. Nobody ever asked you to kill it. never. But we did kindly and friendly ask you to participate instead of doing your little crusades like these days. > A suhosin that is merged to PHP mainline will never provide the same security > as an external solution. > This is not good enough for me. That's your opinion, I'm convinced of the opposite. The issue here is that you lived in the past, based on your experiences with php core years ago, php3/4 and partially 5/5.2. It is really time for you to wake up. > Also PHP.net demands that I convince them to take feature A, B and F from > Suhosin into PHP. It is a standard procedure that applies to any new feature. Many projects do that as well. There is no exception, even for you. > I get ordered to sit down and write RFCs about these features and explain why > they need to go inside. Please double read my replies, I do not see any order but kind suggestions. And yes, I do lobby against Suhosin because I consider it causes more harms to the whole thing that what it solves. That's my rights and I do not engage php.net in my statement but only my personal opinions. And I will continue to lobby, actually not against Suhosin, but to get what PHP needs in PHP and not in some random external patches. I also try to convince you to finally get around your personal issues with us and join our efforts. I do that every time we meet live at conferences or other events. It is also somehow amusing that you are much more polite and nice in a live discussion than through emails, let try to solve that next time we meet :-) Cheers, -- Pierre @pierrejoye | http://blog.thepimp.net | http://www.libgd.org -- PHP Internals - PHP Runtime Development Mailing List To unsubscribe, visit: http://www.php.net/unsub.php