Loading...
 
Skip to main content

History: TikiInSharedHosting

Preview of version: 3

FutureQuest (FQ) has established that their hardware and network are physically capable of accomodating tikiwiki.org. Next step is to determine if TikiWiki would work well in shared hosting environments, their core business.

  1. How server friendly is TikiWiki?
  2. Could our clients easily use this on a Community Server, or would it cause problems for the server?
  3. If all of TikiWiki's features were used by a client, how many (full running) TikiWiki instances could run on a Community Server before it's resource consumption will be noticed...
  4. I would like to see a full manifest documenting all security holes that have been found and fixed... I am mostly interested in seeing how long a security hole is left open before a patch is released...
  5. Something as complex as TikiWiki usually carries a high risk of exploitable flaws, and with TikiWiki running via our PHP Secure_Mode™ setup* - the risk greatly intensifies**... This is because the PHP scripts run as your user and group id, instead of the more generic permissions of the Apache server, and any exploits found and used - will have full access to that site owners account... Our Secure_Mode™ offers a tremendous amount of power and flexibility (no safe_mode), but with that also carries the same risk as what CGI scripts have...

* Secure_Mode™ is an underlying nomenclature for our proprietary high speed low overhead mechanisms that allow Apache to elevate the privileges of an embedded PHP engine from an:

==>request> unprivileged ==> privileged ==>results> unprivileged

for that particular PHP execution phase... It by no means suggests sandboxing, chrooting, or any other type of security measure other than helping to solidify privacy...
**PHP scripts are notoriously more lax when it comes to secure programming, mostly because the web author assumes that it will not be running with the full user and group privileges of the site owner, but rather with unprivileged/generic rights...


FQ: The above listed items must be weighed very carefully, because a side-effect of sponsoring the hosting of this, we are in effect endorsing TikiWiki and putting forth an implied message that it is OK for site owners to run this on our servers... It would be terribly embarrassing if it was later found that TikiWiki is simply too heavy for clients to run on a Community Server and we had to place the application on our Community Server watchlist or blacklist...

History

Information Version
Philippe Cloutier 5
View
Terence? 4
View
Terence? 3
View
Terence? 2
View