4 ms·
Using PHP in 2022+ should be considered a crime of negligence.
by YATA0 5y ago
Using PHP in 2022+ should be considered a crime of negligence.
- unfocussed_mike 5y agoWhy, specifically? I mean, it has problems, sure, but all languages do. What should those negligent people use instead, particularly? What's your suggestion for an alternative system that is as deployable?
- theamk 5y agoI'd personally prohibit all PHP websites that require directories which are writeable + executable. This means basically every app which can be updated from web interface, or has plugins which can be installed from web interface -- Wordpress being a primary example. I understand that it is convenient to deploy, but a single exploited vulnerability can turn a web server into a part of botnet, forever. And this has happened, numerous times. I don't have a specific suggestion for alternate system, but it should have a very clean separation between "code" and "data", and have a very easy way to completely replace "code" part. This can be done with Docker, or deb-style installation, or just a sane design which keeps things separately. And of course you can do it with modern PHP.. it's just that language makes it so easy to do the insecure thing. "I'll just make an uploads/ right next to my index.php, so users don't have to mess with server config too much" - and bam, you have a vuln. Compare it with Golang, or Java -- you'd have to work real hard to make this kind of vulnerability there.
- unfocussed_mike 5y agoAll reasonable points. Aside from WP installs I definitely lock down PHP execution to the single entry point; it's possible to do it with WP too, there are just a few more entry points, alas.
- theamk 5y agoI am sure you do, but what about average PHP programmer? There are thousands of tutorials on the web which teach the insecure way. And even in this thread, there are many people who mention "ease of deployment" as #1 PHP advantage -- do you think they'll lock down their installs? So if starting a new project, you either have a choice of going with PHP and trying to re-educate many experienced PHP programmers that their best practices are insecure... or maybe choosing some other language, like Golang and Python, instead. Those languages are secure by default, there is no need to force people to go against the grain.
- unfocussed_mike 5y agoWith the greatest of respect I don't care about the average programmer anymore. People can be incompetent in all sorts of languages. I care about my own work. I've implicitly mentioned "ease of deployment" myself in this thread, I think, and probably in others, and I don't care for the assertion. I suggest you ask the others who have, what they mean. "Secure by default" is a big claim. Secure against this particular problem you identify, sure. But let's not over-egg the pudding; there are still vulnerabilities in popular Python frameworks.
- spartanatreyu 5y agoComing from someone who doesn't use php except when they have to: PHP today is so so SO much better then the blubbering eldritch horror that was php 4/5. I'm still not going to use it until they fix the ad-hoc/chaotic naming of their built in functions, but it seems there's a proposal to alias all their functions to new names that make sense and are consistent with each other. When that happens php will not just be widely productive, it'll be widely liked too.