5 ms·
PHP may be one weird concoction, that's for sure, but all of the arguments brought up by this guy - and this is the exact same boring song belched out whenever
by hackermom 16y ago
PHP may be one weird concoction, that's for sure, but all of the arguments brought up by this guy - and this is the exact same boring song belched out whenever there's an argument of "PHP is a terrible language" - fall into the category of vanity, because no matter how one twists and turns these points they still really don't make the language itself terrible, and they don't make PHP one bit less capable, nor one bit less adequate for the supposed job.
- Daishiman 16y agoWhat do you mean?? Do you have any idea of just how many programmer hours have been wasted by the absence of features, just how insecure so many web apps are due to the weird casting system and lack of safety-oriented features. My impression is that people who claim PHP has not cost them development time have simply never looked at alternatives that solve many of the problems.
- hackermom 16y agoWithout going off on a limb, I'm guessing you're a not too experienced developer. You comment as if instead going for Perl, Ruby or ASP inherently makes an application safe, saves buttloads of manhours etc. And you're wrong. Gravely wrong. Excluding the obvious issues caused by bugs that are a natural part of any programming language's development, security problems are not caused by the language chosen, but by the developers themselves.
- chromatic 16y agoA well designed language or library can decrease the likelihood of specific bugs, and especially security problems. Imagine the existence of a library which made it easier to use SQL placeholders than to concatenate user input into a string. Imagine PHP without register globals.
- hackermom 16y agoPHP already does that via PDO. PHP's "Register globals" was deprecated exactly one year ago, in 5.3.0.
- moell 16y agoThat was exactly chromatic's point---language design and features do make a difference.
- hackermom 16y agoIt's always easier to blame the tool for your failed craft than it is to be a good programmer, isn't it :) Putting PHP in the "inadequate corner" or trying to convince oneself that it is lacking in features is just an easy excuse.
- chromatic 16y agoIt's always easier to blame the tool for your failed craft than it is to be a good programmer, isn't it :) Do you object to the attractive nuisance doctrine?
- Daishiman 16y agoReally? So the fact that you are unknowingly casting integers to strings and vice-versa does not lead to security vulnerabilities is just fiction? Being able to escape characters? Making prepared statements and having sane exception management? If your statement were true, then by that measure making a program in assembly would be as safe as doing it in C#. Evidently, it is not. Languages make certain idioms easier or worse, and they have a culture of security or they do not, which is reflected in development methodologies, libraries, and code samples. PHP fails massively in all those regards.