7 ms·
PHP 8.0.0 Alpha 1 available for testing
- xiaodai 6y agoIs php really that bad? People keep telling me it's insecure by default.
- solraph 6y agoIt's insecure by default, in the same way that Windows is a 32 bit shell over a 16 bit DOS core, and doesn't have real memory protection. It used to be true, and was a valid criticism. It hasn't been true in so long, that claiming so says more about the claimer than the language.
- muldvarp 6y ago> It used to be true, and was a valid criticism. It hasn't been true in so long, that claiming so says more about the claimer than the language. Not saying that you are wrong here, but what insecure-by-default parts of the language have been changed since PHP 5?
- solraph 6y agoPrincipally, the Register Globals change that turned every POST & GET entry into a variable was removed entirely in PHP 5.4 (1st of March, 2012), and the was old Mysql API was removed in PHP 7.0 (3rd of December, 2015).
- pwdisswordfish2 6y agoThe analogy is a false one. PHP was never re-written from scratch in a way that Windows was (with NT). Most of PHP’s pitfalls are still there, and only now are they being slowly removed one by one.
- solraph 6y agoAnalogies are by their nature imperfect. The analogy here is that <item> is being criticised in ways that are no longer true, where <item> in the case of PHP is specfically "insecure by default", regardless of it's many other flaws. Seems fair to me.
- mekster 6y agoFunny when people complain about PHP is bad, I don't tend to find any specific reference. If bashing others' work make you feel cool, then you need to start checking the facts. My complaint is the inconsistency in the function parameter orders of same categories and the fact it's one of the few languages that still require semi colons at end of lines. Former is pretty much unfixable though unless they introduce same features through new objects. And the newly introduced typing is just too basic after you've gone through TypeScript but this can be improved.
- steve_adams_86 6y agoI don’t love the design of the language, but it’s far from bad as a whole. It’s easy to critique, but hard to rival how easy it is to get things done with it. Also the php community has developed some of the nicest software I’ve used for creating web applications. I don’t use it anymore, but my years working with Symfony were very positive. Overall I’d say it’s a good language and a great community. I don’t personally want to go back to writing php, but I wouldn’t complain if I needed to. I think people remember how abysmal php was around 10 years ago. It was miserable.
- stevekemp 6y agoThe next time somebody tells you that ask for details. What is insecure about it? e.g. Would it be that it would be possible YOU might write a script with a security hole? Because if that is the case then the same could be said of bash-scripts, ruby on rails, and all the other languages out there.
- muldvarp 6y ago> e.g. Would it be that it would be possible YOU might write a script with a security hole? Because if that is the case then the same could be said of bash-scripts, ruby on rails, and all the other languages out there. Well, that's obviously true of any turing complete language. A language can still make it easy or hard to write software with security holes. And it is way to easy to write insecure software in PHP in my personal opinion.
- stevekemp 6y agoThat was my point really, users can write security issues in any language. So why would somebody immediately say "PHP is insecure"? Without any details it's pointless noise.
- muldvarp 6y ago> So why would somebody immediately say "PHP is insecure"? Without any details it's pointless noise. "PHP is insecure" is of course a bad argument to make without at least some explanation, but that doesn't automatically make PHP a good language to write (hopefully) secure software in.
- mekster 6y agoWhen are you going to make some examples of how insecure PHP is?
- kuroguro 6y agoIf you use any modern framework you're mostly covered. SQLi gets handled by ORM and XSS by the templating system which should be "secure" by default. SQLi has been made harder to pull off in the language itself too as all DB queries run trough the PDO interface (for more than 10 years now, I think?). Oh and let's not forget the magic quotes... been gone for a very long time but I still get nightmares about that "feature". The problem used to be that PHP itself started as a templating language - you were supposed to mix HTML and PHP in one file. Easy to do and easy to make bugs. These days almost no one writes a large project without a decent framework. I'd say both the language and the ecosystem of libraries/frameworks have matured a lot over the years but you still have to follow best practices just like any other language. I highly doubt other languages are more "secure" by default.
- tluyben2 6y ago> you were supposed to mix HTML and PHP in one file. Easy to do and easy to make bugs. I maintain a large project (inherited) that has that; cannot say it's been that bad in my experience; it has been running for 20 years and used (internally and externally; it's a crm/erp/everything system) used by 1000s daily; no significant bugs have been reported and adding/changing features is fast and painless. I sometimes wonder if that over-architected stuff we have been taught really is much better. For most things here I change one (or 2) file, test, deploy, done. For most other stuff I maintain, for every change I have to change 5-10 files all over the place (service layers, data layers, migrations etc) and the result is not really better (I would say actually worse generally). It's not really apples vs apples (for starters, it is only used by this company and it's partners, while other systems are running publicly and have far more users and people trying to hack/break things) but this old system is causing me far less headaches than many others while it's far larger and more complex functionality wise. Edit: many companies came in 'offering' a rewrite but yeah.. This costs nothing to host and barely anything to maintain (compared to the revenue of the company) ; all other solutions or rewrites would cost a lot to create/set up and then a lot to run/maintain as well. It's a good example of a company that would be insane to 'go cloud'. Not many benefits but a nice bite in the profit.
- 6y ago
- ragnese 6y agoPHP as a language really is that bad. It's probably the worst popular language right now as far as how difficult it is to write correct code. Especially because a lot of times your code will seem to run fine until it doesn't. It's also got a tacked on type system that is not robust or expressive at all, so your typing is worse than pre-generics Java. Only JavaScript rivals it. It has no async/multi-threading either, so probably JavaScript is less-bad. I don't know that I'd call it insecure, necessarily. I'd call C an insecure language. I'm not an expert on all the various standard library functions that you aren't supposed to use anymore. Just make sure if you do SQL that you go through some interface that prepares your statements for you and never just shove user input into a SQL string you build yourself. On the other hand, as people have already mentioned, there are some genuinely best-in-class libraries and frameworks written in/for PHP. Laravel and Symfony are extremely productive, pretty easy, full-featured, and polished. It's my opinion that people who defend PHP as a language mostly fall into two camps: 1. They've never (significantly) used languages that are much better. Maybe they've only done PHP, JavaScript, Java, and C; and think that all languages are pretty bad. 2. They are conflating the language with the ecosystem. When you choose Laravel for a project, you're choosing a solid framework in spite of PHP-the-language. You're probably not really choosing PHP per se.
- mns 6y ago"It has no async/multi-threading either, so probably JavaScript is less-bad." Screwdrivers are really that bad, you can't even use them to pound a nail properly...
- ragnese 6y agoWhat? PHP is a language primarily for backend web server code. Having async is huge for performance on the backend, which is mostly IO bound, rather than CPU bound. So, I think you have it backwards. Async is unnecessary in many places, but backend is the place where it's very important.
- mns 6y agoPHP started as a scripting language and had/has many other issues and fundamentals that had/has to get right first. Don't blame PHP or Javascript for things they were not initially built and meant for, when there are other languages out there that can do what you need and have a more solid and tested foundation.