I have to know. Is this a play on the ever-so-popular <a href="https://eev.ee/blog/2012/04/09/php-a-fractal-of-bad-design/" rel="nofollow">https://eev.ee/blog/2012/04/09/php-a-fractal-of-bad-design/
Yes it is, good catch. It's even linked under the text "especially at the time" in the post. I probably should have referenced it more prominently, but I thought it was a fun Easter egg under a more subtle link.
As the post mentions, I worked on the DAG (an on-prem IdP implementation) for many years, which was based on simpleSAMLphp. So "PHP: a fractal of bad design" was our other north star after the SAML specs for avoiding critical security issues. I spent many hours poring over that blog post trying my best to avoid PHP bugs.
Here was a fun one that occurred due to PHP's wonky in_array behavior: <a href="https://simplesamlphp.org/security/201710-01" rel="nofollow">https://simplesamlphp.org/security/201710-01
bigquama · · focus · HN ↗
schwag09 · · focus · HN ↗
As the post mentions, I worked on the DAG (an on-prem IdP implementation) for many years, which was based on simpleSAMLphp. So "PHP: a fractal of bad design" was our other north star after the SAML specs for avoiding critical security issues. I spent many hours poring over that blog post trying my best to avoid PHP bugs.
Here was a fun one that occurred due to PHP's wonky in_array behavior: <a href="https://simplesamlphp.org/security/201710-01" rel="nofollow">https://simplesamlphp.org/security/201710-01