4 ms·
> First, why on earth would you still be using non-parametrized queries. Legacy software no one wants to maintain, and no one is paid to maintain.
by Denvercoder9 6y ago
> First, why on earth would you still be using non-parametrized queries.
Legacy software no one wants to maintain, and no one is paid to maintain.
- acdha 6y agoIt’s worse than that: the advice to use parameterized queries goes back to the late 1990s before that legacy software was even started. The problem is that it’s ever so slightly more work and some people will say “I’m busy, I’ll be smart enough to always escape my inputs” and will get the CVEs to prove it. Unfortunately, some of the core developers were in that camp so PHP 4 came without improvements, PDO avoided the opportunity to be safer, etc. register_globals had a similar arc: people knew it was a risky feature before the turn of the century but turning it off would inevitably get someone whining about how hard it was to explicitly import their variables or check both GET and POST, as if this wasn’t trivially abstracted. A lot of this goes back to 90s C / Unix culture. PHP was a product of that world and had the same “Real Programmers™ check their inputs & return codes. If your code breaks, it’s your fault for not being a Real Programmer™ and I don’t want to be slowed down by safety checks intended for you.” attitude which has taken decades to stamp out.
- oblio 6y ago> which has taken decades to stamp out You optimist. I think we're still trying to stamp it out :-)
- acdha 6y agoIt’s definitely not gone but I feel like it’s shifted to a defensive posture & not getting many new adherents. Part of that is probably better hardware & languages making the performance and developer productivity arguments less persuasive.
- Denvercoder9 6y ago> It’s worse than that: the advice to use parameterized queries goes back to the late 1990s before that legacy software was even started MySQL didn't introduce prepared queries until 4.1, which was released in 2004.
- acdha 6y agoYes - this was a common criticism if you were trying to get MySQL into an environment with a different database since this was a SQL92 feature which was good for performance and security. That had often been seen as a performance move or a way to avoid confusing error messages but that started to change by the turn of the century as the technique became more visible and so many web apps were fronting databases rather than static. Poking around https://metacpan.org/pod/DBI https://metacpan.org/pod/DBI I notice support added by some point in 1997, possibly as early as 1996. Python’s DBI spec had it no later than 2001. The other thing to remember is that it wasn’t uncommon to have drivers emulate this behavior on databases which didn’t have protocol level support for it. That didn’t help performance but it did accomplish the goal of making sure that data wasn’t confused with code. To be clear, I’m basing my comments on having used PHP professionally starting with PHP 3 for many projects, including some household name companies. I trained a fair number of people, some of my earliest open source work was in PHP, etc. so I don’t hate the language but I definitely think there are cautionary lessons to learn about the value of defaults and how languages are taught. As we’ve seen with C, telling people to be more diligent is less effective than making the default safe behavior you have to opt out of rather than the reverse.
- todotask 6y agoIt's amazing that the Internet have evolved a lot, ton of open source software has been developed, web framework authors been participated in lots of ways for their community and cloud computing are widespread. WordPress is still using non-parameterized queries, it is assume they have been battle tested over the years. While PHP is 26 years old, we are not surprise legacy software are still existed.
- remram 6y agoNo one had to maintain it though, they could have moved to GitHub or GitLab at any time, or use one of the many open-source self-hostable solutions like Gitea, Phabricator (it's PHP), GitLab, ...
- Denvercoder9 6y agoThat still requires someone to do the migration. Don't forget that aside from VCS, this system also integrates with their bugtracker, wiki, etc.