Custodians of PHP vote to keep a crypto lib abandoned in 2003 in PHP 7
thefsb.tumblr.com
thefsb.tumblr.com
Things as simple as fixing ternary associativity that has been broken and discouraged forever are basically DOA because it may break some tiny % of code that relies on broken behavior. They have a valid point that simply fixing it will break code in silent ways. So there was a possibility of making it unassociative in 7.0, throwing a warning and only fixing it for real in 5 years during the next major cycle. I don't know if this migration path will even happen.
Compatibility is the only thing PHP has going for it right now. It feels like the only PHP apps out there are 'legacy' ones, new projects are written in newer stuff.
Over 34,000 repos created on Github since Jan 1 that have PHP as the main language: https://github.com/search?utf8=✓&q=created%3A%3E2015-01-01+l...
Seems like he just enjoys getting mad at people about their decisions. There's reasons for this decision, and as a PHP developer, I see why tearing out mcrypt could be problematic. Pretty lame that he's shitting all over these guys because they did their job and made a judgement call.
a: "Most of our users don't care about security."
b: "OK then they can continue using old broken versions."
a: "No, then they won't be secure! Therefore it must be easy to upgrade."
b: "How?"
a: "By not making the proposed security improvements."
This seems like a recipe for losing any users that do care about security, which is not a viable strategy over the long term.PHP folks need to remove head from ass. (disclaimer: I love PHP - as a language)