<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: PHP 5.3 Not In Next Version Of Ubuntu</title>
	<atom:link href="http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/</link>
	<description>The personal blog of Brandon Savage. Contains entries of a personal and professional nature focusing on PHP, Apple, LAMP, MySQL and Washington, DC.</description>
	<lastBuildDate>Thu, 29 Jul 2010 11:09:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Brandon Savage</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-969</link>
		<dc:creator>Brandon Savage</dc:creator>
		<pubDate>Wed, 19 Aug 2009 19:39:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-969</guid>
		<description>I&#039;ll not be bullied into taking a position I know to be untrue, especially by small minds. I&#039;ll also not restate my arguments, which I&#039;ve already made.

I will say that I use Suhosin on my own server, due to the fact that I make use of Wordpress and it&#039;s plugins. I don&#039;t have time to review every single line of Wordpress code, nor do I have the desire to do so; instead I rely on the hardening patch to help defend the system.</description>
		<content:encoded><![CDATA[<p>I&#8217;ll not be bullied into taking a position I know to be untrue, especially by small minds. I&#8217;ll also not restate my arguments, which I&#8217;ve already made.</p>
<p>I will say that I use Suhosin on my own server, due to the fact that I make use of WordPress and it&#8217;s plugins. I don&#8217;t have time to review every single line of WordPress code, nor do I have the desire to do so; instead I rely on the hardening patch to help defend the system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Federico</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-968</link>
		<dc:creator>Federico</dc:creator>
		<pubDate>Wed, 19 Aug 2009 18:16:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-968</guid>
		<description>Admit it. What you said about developers getting offended is nonsense. Maybe you got offended? Your boss installed the patched?</description>
		<content:encoded><![CDATA[<p>Admit it. What you said about developers getting offended is nonsense. Maybe you got offended? Your boss installed the patched?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon Savage</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-964</link>
		<dc:creator>Brandon Savage</dc:creator>
		<pubDate>Wed, 19 Aug 2009 10:49:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-964</guid>
		<description>I don&#039;t &quot;have&quot; to produce anything. When even the makers of the patch admit that some features have a measurable speed impact (http://www.hardened-php.net/hphp/faq.html#general) insisting that I provide evidence when they&#039;ve already admitted it makes you look like a fool. I&#039;m not the one who says that Suhosin has a performance impact, the makers of Suhosin are. Q.E.D.

I&#039;d like to know what on this list (http://www.hardened-php.net/hphp/a_feature_list.html) you think wouldn&#039;t be already handled by making use of already established best practices. Suhosin provides a great set of features to make sure that a noob developer doesn&#039;t run amok on your system, but a seasoned developer will avoid these practices by default.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t &#8220;have&#8221; to produce anything. When even the makers of the patch admit that some features have a measurable speed impact (<a href="http://www.hardened-php.net/hphp/faq.html#general" rel="nofollow">http://www.hardened-php.net/hphp/faq.html#general</a>) insisting that I provide evidence when they&#8217;ve already admitted it makes you look like a fool. I&#8217;m not the one who says that Suhosin has a performance impact, the makers of Suhosin are. Q.E.D.</p>
<p>I&#8217;d like to know what on this list (<a href="http://www.hardened-php.net/hphp/a_feature_list.html" rel="nofollow">http://www.hardened-php.net/hphp/a_feature_list.html</a>) you think wouldn&#8217;t be already handled by making use of already established best practices. Suhosin provides a great set of features to make sure that a noob developer doesn&#8217;t run amok on your system, but a seasoned developer will avoid these practices by default.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Federico</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-963</link>
		<dc:creator>Federico</dc:creator>
		<pubDate>Wed, 19 Aug 2009 06:55:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-963</guid>
		<description>You have to produce some benchmarks, otherwise there&#039;s no reason for not using it. What you said about developers getting offended is nonsense.</description>
		<content:encoded><![CDATA[<p>You have to produce some benchmarks, otherwise there&#8217;s no reason for not using it. What you said about developers getting offended is nonsense.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin van Zonneveld</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-901</link>
		<dc:creator>Kevin van Zonneveld</dc:creator>
		<pubDate>Wed, 12 Aug 2009 10:05:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-901</guid>
		<description>Correct me if I&#039;m wrong. But I interpreted the meeting minutes slightly different.

&quot;Once the suhosin patch is ported to 5.3 and enabled in the build 5.3 can be uploaded to karmic. &quot;

To me says: there&#039;s still time to do the suhosin patch and then get in in Karmic. Given the fact that there already is an unofficial suhosin patch out there, I&#039;m feeling chances are actually pretty good.

But I could be overlooking something.
Anyway, there&#039;s something going on here as well:
https://bugs.launchpad.net/ubuntu/+source/php5/+bug/394385</description>
		<content:encoded><![CDATA[<p>Correct me if I&#8217;m wrong. But I interpreted the meeting minutes slightly different.</p>
<p>&#8220;Once the suhosin patch is ported to 5.3 and enabled in the build 5.3 can be uploaded to karmic. &#8221;</p>
<p>To me says: there&#8217;s still time to do the suhosin patch and then get in in Karmic. Given the fact that there already is an unofficial suhosin patch out there, I&#8217;m feeling chances are actually pretty good.</p>
<p>But I could be overlooking something.<br />
Anyway, there&#8217;s something going on here as well:<br />
<a href="https://bugs.launchpad.net/ubuntu/+source/php5/+bug/394385" rel="nofollow">https://bugs.launchpad.net/ubuntu/+source/php5/+bug/394385</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon Savage</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-899</link>
		<dc:creator>Brandon Savage</dc:creator>
		<pubDate>Tue, 11 Aug 2009 20:59:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-899</guid>
		<description>I haven&#039;t tried to apply the patch. I&#039;m waiting for the official patch.</description>
		<content:encoded><![CDATA[<p>I haven&#8217;t tried to apply the patch. I&#8217;m waiting for the official patch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vladimir</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-898</link>
		<dc:creator>Vladimir</dc:creator>
		<pubDate>Tue, 11 Aug 2009 20:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-898</guid>
		<description>Sorry, the link is broken. Should be http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/</description>
		<content:encoded><![CDATA[<p>Sorry, the link is broken. Should be <a href="http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/" rel="nofollow">http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vladimir</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-897</link>
		<dc:creator>Vladimir</dc:creator>
		<pubDate>Tue, 11 Aug 2009 20:40:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-897</guid>
		<description>Has anyone tested the modified Suhosin patch from Arnold (http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/)?</description>
		<content:encoded><![CDATA[<p>Has anyone tested the modified Suhosin patch from Arnold (<a href="http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/)?" rel="nofollow">http://blog.adaniels.nl/articles/suhosin-patch-for-php-53/)?</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Federico</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-852</link>
		<dc:creator>Federico</dc:creator>
		<pubDate>Fri, 07 Aug 2009 16:13:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-852</guid>
		<description>Hi Brandon,

&gt; and that have a serious performance impact on PHP itself (sohosin does impact performance considerably in several areas).

I think it should be optional as well, specially if it has a huge impact in performance, like you said. Do you have any benchmarks of this? Thanks.</description>
		<content:encoded><![CDATA[<p>Hi Brandon,</p>
<p>&gt; and that have a serious performance impact on PHP itself (sohosin does impact performance considerably in several areas).</p>
<p>I think it should be optional as well, specially if it has a huge impact in performance, like you said. Do you have any benchmarks of this? Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan Esser</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-848</link>
		<dc:creator>Stefan Esser</dc:creator>
		<pubDate>Thu, 06 Aug 2009 13:57:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-848</guid>
		<description>Suhosin for PHP 5.3.0 will be released when I am finally at home again next week. Due to some of the new features in the patch it turned out to be a bigger task than expected and therefore it was not possible to release it before I left for conferences and vacation.

One of the new features will be a certain amount of protection against the PHP security holes I presented at Blackhat about. You won&#039;t get this protection in vanilla PHP.</description>
		<content:encoded><![CDATA[<p>Suhosin for PHP 5.3.0 will be released when I am finally at home again next week. Due to some of the new features in the patch it turned out to be a bigger task than expected and therefore it was not possible to release it before I left for conferences and vacation.</p>
<p>One of the new features will be a certain amount of protection against the PHP security holes I presented at Blackhat about. You won&#8217;t get this protection in vanilla PHP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon Savage</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-846</link>
		<dc:creator>Brandon Savage</dc:creator>
		<pubDate>Wed, 05 Aug 2009 23:58:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-846</guid>
		<description>The patch compensates for poor development and security practices, and I&#039;m sure that the core PHP developers feel as though they ought not reward that behavior by including the patch in the core. I, myself, don&#039;t use the patch because of things it interferes with, and I think that if we boil it down a lot of developers would take offense at having to use a security patch that has features they don&#039;t want or need, and that have a serious performance impact on PHP itself (sohosin does impact performance considerably in several areas).</description>
		<content:encoded><![CDATA[<p>The patch compensates for poor development and security practices, and I&#8217;m sure that the core PHP developers feel as though they ought not reward that behavior by including the patch in the core. I, myself, don&#8217;t use the patch because of things it interferes with, and I think that if we boil it down a lot of developers would take offense at having to use a security patch that has features they don&#8217;t want or need, and that have a serious performance impact on PHP itself (sohosin does impact performance considerably in several areas).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-845</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 05 Aug 2009 21:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-845</guid>
		<description>Why doesn&#039;t the PHP team include sohosin instead of making all the distros patch it in for each release?</description>
		<content:encoded><![CDATA[<p>Why doesn&#8217;t the PHP team include sohosin instead of making all the distros patch it in for each release?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fabry</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-841</link>
		<dc:creator>Fabry</dc:creator>
		<pubDate>Wed, 05 Aug 2009 15:12:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-841</guid>
		<description>PHP 5.3.0 is included in Fedora 12

https://fedoraproject.org/wiki/Fedora_12_Alpha_release_notes</description>
		<content:encoded><![CDATA[<p>PHP 5.3.0 is included in Fedora 12</p>
<p><a href="https://fedoraproject.org/wiki/Fedora_12_Alpha_release_notes" rel="nofollow">https://fedoraproject.org/wiki/Fedora_12_Alpha_release_notes</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon Savage</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-840</link>
		<dc:creator>Brandon Savage</dc:creator>
		<pubDate>Wed, 05 Aug 2009 15:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-840</guid>
		<description>No flame perceived.

One thing you can do is add a --prefix=/my/path and this will install PHP in a location of your choosing. Upon the release of the package, you can simply run a rm -fr /my/path and get rid of PHP.

Running your own server inherently comes with these risks, and I think most people who feel comfortable compiling PHP are also comfortable being systems administrators so far as to manage their own installations of things. Example: I manage my own installation of Subversion, and each time I do an update I have to reinstall some part of it. This creates some headaches, to be sure, but it&#039;s part of having the latest version of things.</description>
		<content:encoded><![CDATA[<p>No flame perceived.</p>
<p>One thing you can do is add a &#8211;prefix=/my/path and this will install PHP in a location of your choosing. Upon the release of the package, you can simply run a rm -fr /my/path and get rid of PHP.</p>
<p>Running your own server inherently comes with these risks, and I think most people who feel comfortable compiling PHP are also comfortable being systems administrators so far as to manage their own installations of things. Example: I manage my own installation of Subversion, and each time I do an update I have to reinstall some part of it. This creates some headaches, to be sure, but it&#8217;s part of having the latest version of things.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Sironi</title>
		<link>http://www.brandonsavage.net/php-5-3-not-in-next-version-of-ubuntu/#comment-839</link>
		<dc:creator>Giorgio Sironi</dc:creator>
		<pubDate>Wed, 05 Aug 2009 15:03:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.brandonsavage.net/?p=514#comment-839</guid>
		<description>No flame intended, but installing php by yourself in that way (make install instead of building a deb package) will mess up the system and raise problems when a package will be available via apt-get.</description>
		<content:encoded><![CDATA[<p>No flame intended, but installing php by yourself in that way (make install instead of building a deb package) will mess up the system and raise problems when a package will be available via apt-get.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk (feed is rejected)
Page Caching using apc (user agent is rejected)
Database Caching 43/51 queries in 0.030 seconds using disk
Content Delivery Network via Amazon Web Services: S3: files.brandonsavage.net.s3.amazonaws.com

Served from: www.brandonsavage.net @ 2010-07-31 11:13:21 -->