Of course this is all speculation. It may be truth and someone reconstruct the original version by decompiling it. e.g.: https://github.com/wybory2014/Kalkulator1/commit/cdff9cb67b8...
Of course this is all speculation. It may be truth and someone reconstruct the original version by decompiling it. e.g.: https://github.com/wybory2014/Kalkulator1/commit/cdff9cb67b8...
There are entire languages written with the design goal being security. It's not a matter of whether or not something is a capable tool (ie: runs 23% of the internet), it's whether or not it's the right tool for the job. PHP clearly isn't.
Everyone likes to say security is mission critical, but for the vast majority of people it really isn't. And for those people the development speed advantage, massive developer market, libraries etc. you get working in Ruby or PHP are well worth it.
Everything is tradeoffs, and it seems to me that in writing voting software deployability, development speed etc., are not nearly as mission critical as security.
While I'm inclined to agree, this is a self-defeating premise. If you're "so good" of a programmer that you do not make security affecting mistakes (i.e. one of only a handful of PHP programmers I've met), then the probability of inserting "security issues" into your code is still zero, regardless of language.
> I'm not saying this as some idiot who thinks PHP is bullshit and for noobs, I've worked on pretty large sites using PHP and I have a pretty deep understanding of it.
Good. :)
This is congruent to saying, "Whitelists don't exist. Everyone implements poorly scoped black-lists."
People make mistakes. Systems should be designed for this expectation. If mistakes are extremely costly it implies you should use certain tools and development methodologies, if not you can use others.
For an example of an application that is currently free of application-layer security bugs, see my blog. It's not a CMS, I wrote it myself. Go ahead and try to hack it. :P
Edit: put another way: if you are starting from scratch and your main focus is security, why would you use PHP?