8 ms·
I had the misfortune to use Drupal a while ago. It seemed like a very convenient and powerful way to get an extremely full-featured and rich site up quickly.
by minsight 11y ago
I had the misfortune to use Drupal a while ago. It seemed like a very convenient and powerful way to get an extremely full-featured and rich site up quickly. It was only after attempting one of the frequently-required updates that I realized that its architecture was atrociously bad. I left immediately and never looked back.
- ajsalminen 11y agoI've encountered very little software that does not fairly frequently require (security) updates. It's somewhat irrelevant whether the leak happened through an unpatched security issue in Drupal since they're apparently running the vulnerable version today and the update has been released way back in 2014. The real reason that lead to this is the strategy of running security updates to a public-facing website containing sensitive materials with the frequency of only once every 1-2 years, or worse. Assuming of course that this website is the source of these leaks at all.
- tangue 11y agoI don't think it's irrelevant it shows a pattern in business where people are installing php mysql and apache without realizing what they are doing. I'm pushing for static websites for this reason.
- ajsalminen 11y agoThat's certainly a problem for the low end but I think Mossack Fonseca should definitely know better as a law firm with 500+ employees in over 40 countries.
- snowwrestler 11y agoI don't understand this comment. You left because the updates were frequently required? Or because some aspect of applying the updates was difficult?
- debacle 11y agoThe nature of the application means that any sort of semi-complicated update has to be applied manually to some degree. Think of a database, but instead of a database you have some weird mix of MS Access and irresponsible use of EAV. That's Drupal.
- minsight 11y agoWell put. Also, the developers (at least when I was involved with it) had a thing for repeatedly changing internals such that new developments (most importantly, security-related developments) required orders of magnitude more ability in a variety of esoterica than the install process did.
- minsight 11y agoThe application of updates required manually updating databases. There was an easy-to-use installation procedure but the upgrade process was both not automated and very easy to break. The developers (at least at the time) were more interested in making repeated breaking changes than they were in investing the effort to allow earlier adopters a reliable upgrade process. My irritation was that this was the metaphorical equivalent of a business offering a fantastic deal to new customers but treating existing customers with palpable disdain.
- ajsalminen 11y agoWhat kind of manual steps are you talking about? Updating Drupal is usually fairly straightforward and unless you're talking about an alpha/beta release or doing a major version upgrade and definitely doesn't require manual database changes most of the time.