• 3 Posts
  • 42 Comments
Joined 1 year ago
cake
Cake day: June 13th, 2023

help-circle
















  • witten@lemmy.worldOPtoSelfhosted@lemmy.worldPHP and security
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    That all seems prudent and reasonable. I guess some of my own anxiety is about how exactly I’ll evaluate projects like you’re talking about. I can (and do) certainly look at whether a project is actively developed before selecting it. Not just for security reasons… I don’t want to bet on a horse that won’t get updated with fixes and features. But for security in particular, I guess I was hoping for ways to evaluate that for a project… without exhaustively poring over its source. Maybe, to your point, the other mitigations you listed should be sufficient, and I should worry more about that side of things than picking the perfect project.




  • witten@lemmy.worldOPtoSelfhosted@lemmy.worldPHP and security
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    That makes sense. Maybe then the trick is to look at whether any particular app (PHP or otherwise) is written with modern security practices. How do you judge a project’s security practices though?

    And then, yeah, maybe also lock it down in a container so the blast radius of any actual exploit is pretty minimal.