5 ms·
It's insecure by default, in the same way that Windows is a 32 bit shell over a 16 bit DOS core, and doesn't have real memory protection. It used to be true, a
by solraph 6y ago
It's insecure by default, in the same way that Windows is a 32 bit shell over a 16 bit DOS core, and doesn't have real memory protection.
It used to be true, and was a valid criticism. It hasn't been true in so long, that claiming so says more about the claimer than the language.
- muldvarp 6y ago> It used to be true, and was a valid criticism. It hasn't been true in so long, that claiming so says more about the claimer than the language. Not saying that you are wrong here, but what insecure-by-default parts of the language have been changed since PHP 5?
- solraph 6y agoPrincipally, the Register Globals change that turned every POST & GET entry into a variable was removed entirely in PHP 5.4 (1st of March, 2012), and the was old Mysql API was removed in PHP 7.0 (3rd of December, 2015).
- pwdisswordfish2 6y agoThe analogy is a false one. PHP was never re-written from scratch in a way that Windows was (with NT). Most of PHP’s pitfalls are still there, and only now are they being slowly removed one by one.
- solraph 6y agoAnalogies are by their nature imperfect. The analogy here is that <item> is being criticised in ways that are no longer true, where <item> in the case of PHP is specfically "insecure by default", regardless of it's many other flaws. Seems fair to me.
- mekster 6y agoFunny when people complain about PHP is bad, I don't tend to find any specific reference. If bashing others' work make you feel cool, then you need to start checking the facts. My complaint is the inconsistency in the function parameter orders of same categories and the fact it's one of the few languages that still require semi colons at end of lines. Former is pretty much unfixable though unless they introduce same features through new objects. And the newly introduced typing is just too basic after you've gone through TypeScript but this can be improved.