Live data from Hacker News

Shield, A Security-Minded PHP Microframework

github.com

1–10 of 13 posts

Re: Shield, A Security-Minded PHP Microframework

#2
> Filter values based on filter types (supported are: email, striptags)

Striptags is not a security tool, it is a presentation tool.

> Output filtering on all values (preventing XSS)

I'm still trying to figure out how you've implemented this.

Re: Shield, A Security-Minded PHP Microframework

#3
While I'm not a PHP fan, I sincerely wish the average web developer were more security conscious and so I applaud the effort here. Having been the grouchy security guy on more projects than I can remember, I can attest that it's a thankless and tiresome job. The better you do, the less it will be appreciated.

Re: Shield, A Security-Minded PHP Microframework

#4
post #2

> Filter values based on filter types (supported are: email, striptags) Striptags is not a security tool, it is a presentation tool. > Output filtering on all values (preventing XSS) I'm still trying to figure out how you've implemented this.

Here is the escaping :

https://github.com/enygma/shieldframework/blob/master/Shield...

at this line :

$value = htmlspecialchars($value);

Re: Shield, A Security-Minded PHP Microframework

#5
post #4
post #2

> Filter values based on filter types (supported are: email, striptags) Striptags is not a security tool, it is a presentation tool. > Output filtering on all values (preventing XSS) I'm still trying to figure out how you've implemented this.

Here is the escaping : https://github.com/enygma/shieldframework/blob/master/Shield... at this line : $value = htmlspecialchars($value);

That could do with being mentioned in the README, a large part of the problem with PHP is developers not knowing what method to use to sanitise strings. After seeing striptags mentioned explicitly, I expected the worst.

Re: Shield, A Security-Minded PHP Microframework

#7
Yes, let's all use a security framework by a guy who thinks DES is a good choice, and who openly admits that this is a learning experience for him, this security framework he's giving to others.

Clearly, if after it's pointed out that DES is a bad idea he still doesn't know why, but he also refuses to fix it or take it down, the rest of this should be trusted too.

Re: Shield, A Security-Minded PHP Microframework

#8

Before anyone else brings it up, there are some issues with the session handler function. I'm working on a write-up and pull-request for them to fix the broken cryptography used there.

That's the least of the problems here.

Not every library can be saved.

Re: Shield, A Security-Minded PHP Microframework

#9
post #5
post #4

Earlier quoted context omitted.

Here is the escaping : https://github.com/enygma/shieldframework/blob/master/Shield... at this line : $value = htmlspecialchars($value);

That could do with being mentioned in the README, a large part of the problem with PHP is developers not knowing what method to use to sanitise strings. After seeing striptags mentioned explicitly, I expected the worst.

He used DES for session security.

That's the worst.

Re: Shield, A Security-Minded PHP Microframework

#10

Yes, let's all use a security framework by a guy who thinks DES is a good choice, and who openly admits that this is a learning experience for him, this security framework he's giving to others. Clearly, if after it's pointed out that DES is a bad idea he still doesn't know why, but he also refuses to fix it or take it down, the rest of this should be trusted too.

Where did he refuse to fix it? I'm confused. I've talked with him directly, and we're in progress on a complete fix for that issue (the cryptography issues in the session class)...
Post reply on HN