4 ms·
Without going off on a limb, I'm guessing you're a not too experienced developer. You comment as if instead going for Perl, Ruby or ASP inherently makes an appl
by hackermom 16y ago
Without going off on a limb, I'm guessing you're a not too experienced developer. You comment as if instead going for Perl, Ruby or ASP inherently makes an application safe, saves buttloads of manhours etc. And you're wrong. Gravely wrong.
Excluding the obvious issues caused by bugs that are a natural part of any programming language's development, security problems are not caused by the language chosen, but by the developers themselves.
- chromatic 16y agoA well designed language or library can decrease the likelihood of specific bugs, and especially security problems. Imagine the existence of a library which made it easier to use SQL placeholders than to concatenate user input into a string. Imagine PHP without register globals.
- hackermom 16y agoPHP already does that via PDO. PHP's "Register globals" was deprecated exactly one year ago, in 5.3.0.
- moell 16y agoThat was exactly chromatic's point---language design and features do make a difference.
- hackermom 16y agoIt's always easier to blame the tool for your failed craft than it is to be a good programmer, isn't it :) Putting PHP in the "inadequate corner" or trying to convince oneself that it is lacking in features is just an easy excuse.
- chromatic 16y agoIt's always easier to blame the tool for your failed craft than it is to be a good programmer, isn't it :) Do you object to the attractive nuisance doctrine?
- Daishiman 16y agoReally? So the fact that you are unknowingly casting integers to strings and vice-versa does not lead to security vulnerabilities is just fiction? Being able to escape characters? Making prepared statements and having sane exception management? If your statement were true, then by that measure making a program in assembly would be as safe as doing it in C#. Evidently, it is not. Languages make certain idioms easier or worse, and they have a culture of security or they do not, which is reflected in development methodologies, libraries, and code samples. PHP fails massively in all those regards.