3 ms·
Some languages make writing secure code easier than others. When it comes to web-related code of semi-good programmers, I'd conjecture that the amount of vulner
by nikic 13y ago
Some languages make writing secure code easier than others. When it comes to web-related code of semi-good programmers, I'd conjecture that the amount of vulnerabilities is directly proportional to the amount of magic involved. Early PHP had lots of magic - things like register globals or magic quotes. By now no sane developer uses those things anymore (well, and they were removed). The plethora of recent Rails vulnerabilities was also caused by various magical behavior, especially in parameter parsing. (Actually, I'd expect modern Rails code to have more vulnerabilities than modern PHP code, because they still have a lot more magic involved.)