> Thirdly the PHP team have historically had a rather cavalier  
> attitude to security. They've implemented a number of mechanisms  
> (register globals, URL wrappers for fopen et al, etc) that have  
> favoured ease of use over security.

And while modern PHPs do the "right thing" (e.g. switch off  
register_globals by default), there are still a lot of people whose  
first step is to switch it back on again :-)


