[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Technical committee acting in gross violation of the Debian constitution



On Dec 04, Christoph Anton Mitterer <calestyo@scientia.net> wrote:

> > While using many more times the resources. You obviously have no idea of 
> > the challenges of providing secure web hosting for non-trivial 
> > quantities of web sites.
> So what do you want to imply would be secure?
The point is not just "secure", but "secure and scalable".
And sadly the only good solution that fits this criteria is php-cgi with
some kind of uid-changing wrapper.

> Apart from that, when you speak of "non-trivial" quantities - I'd
> probably say that running gazillion websites from different entities on
> one host is generally a really bad idea.
Web hosting is a complex business.

> > FastCGI is another thing that almost nobody can afford when hosting 
> > a significant number of web sites.
> Why not?
Because RAM is expensive and you cannot keep tens or even thousands of 
fastcgi processes around waiting for a request.

> So I wouldn't see anything (except XYZ should run insecurely
> out-of-the-box) which makes mod-php better in any use case than the
> alternatives.
This is correct.

-- 
ciao,
Marco

Attachment: pgpRS0Z_IGBKY.pgp
Description: PGP signature


Reply to: