What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.
Phpfog "Down for maintenance"
11–20 of 125 posts
Re: Phpfog "Down for maintenance"
#12What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.
Atleast they were kind enough to remove all API keys and passwords from the code dump.
Re: Phpfog "Down for maintenance"
#13What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.
Re: Phpfog "Down for maintenance"
#14Re: Phpfog "Down for maintenance"
#15Earlier quoted context omitted.
Depends on the type of instance they spin up, but I would definitely tend to agree with you! Security in shared hosting is extremely hard (I used to be a sys admin for a hosting company in a prior life), especially since there is no good way to separate everyone from each other without making performance suck completely, FreeBSD jails alleviate some of it, but you start having scalability issues, PHP running in php-f…
Heroku has done it reasonably well too and they seem to do it only with POSIX permissions for the most part.
Re: Phpfog "Down for maintenance"
#16What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.
A mirror of the code dump (referred to in a tweet linked in this discussion) is hosted on a 16 webdev from Australia... Atleast they were kind enough to remove all API keys and passwords from the code dump.
This can't be legal.
Re: Phpfog "Down for maintenance"
#17Re: Phpfog "Down for maintenance"
#18Re: Phpfog "Down for maintenance"
#19When is the funeral of phpfog being hosted?
Re: Phpfog "Down for maintenance"
#20What a dick move. Did these idiots actually publish their names in relation to this? Coming from "security experts" this is the most unprofessional thing I've ever seen.
A mirror of the code dump (referred to in a tweet linked in this discussion) is hosted on a 16 webdev from Australia... Atleast they were kind enough to remove all API keys and passwords from the code dump.