4 ms·
Probably contrary to common belief here but the headline is correct IMHO. However this is because web programming as a whole is a crock from top to bottom. PHP
by thirdsight 13y ago
Probably contrary to common belief here but the headline is correct IMHO.
However this is because web programming as a whole is a crock from top to bottom. PHP doesn't really add or subtract from that other than lowering the barrier to entry with respect to compromising your server through stupid architectural or coding decisions.
If we wrote our web pages in C, it's be just as bad. Rails has a terrible history of vulnerabilities. Many times I've seen injection attacks in audited Java and C# applications.
Everything can be a turd in the wrong hands.
- mschuster91 13y agoIn contrast, I'd say a pure-C web page would be way easier to open to attacks than a PHP one. String copy issues (termination), buffer/array overflows, machine-code (R)CE vulnerabilities,... an endless list of stuff which the PHP runtime actually protects a novice of.
- cleverjake 13y agoand a webpage written in assembly would be even more likely to be able to be attacked. Its a silly argument. No one is saying consider C for you next website.
- thirdsight 13y agoActually I am considering C. It's pretty easy to write a CGI that Apache can call. Process startup is pretty cheap on UNIX and it's secure if you suexec, chroot it and know how to write C code that isn't full of holes. http://undeadly.org/ http://undeadly.org/ is written in C. Source: http://undeadly.org/undeadly-src.tar.gz http://undeadly.org/undeadly-src.tar.gz
- jorgecastillo 13y agoWow! I didn't know that, I've always thought it was written in Perl.
- thirdsight 13y agoYes but it only takes one eval or config flag set wrongly for that to be moot. It's perfectly possible to write a pure C web page that is 100% secure. It just requires experience. The same with all other languages. PHP doesn't protect the novice, neither does C. Experience does.
- ihsw 13y ago> Yes but it only takes one eval or config flag set wrongly for that to be moot. The same could be said about any language, however 'never use eval' is usually shouted quite loudly at anyone learning a scripting language.
- cleverjake 13y ago> Probably contrary to common belief here I don't think that is true. PHP just makes it easy to write anything - including insecure code. And the bigger issue is that the community around PHP often shares code that is insecure without knowing that it is, or why that would be important. The C argument is a red herring - its not meant for web pages. (web servers, though...) Rails is not a language. It is a framework. Wordpress has tons of vulns as well. I agree that "Everything can be a turd in the wrong hands", however, one of the biggest parts of, er, "turd prevention" is the culture and tribal knowledge around a language and best practices. PHP struggles with that because it is so easy to learn and so easy to do something bad.
- einhverfr 13y agoI think one issue is that there are a number of somewhat dangerous foot-guns security-wise in extension-land. For example, last I checked the pgsql extension had implicit, global, anonymous database connections. Culture is part of it, but part of the culture is figuring out how to ensure that programmers can verify security. Yes, anyone can write insecure code in any language, but can anyone write provably reasonably secure code in a given language? That's a far harder question. I don't see PHP scoring very well in that regard.
- draginator 13y agoPHP makes it easy to do easy things terribly, but makes it extremely difficult to do normal things well.