216 karma · joined February 15, 2018
Yes, PHP has been "cleaned up" and you have always had the option to use clean, concise way of coding without language interfering or hindering you in any way.
There's no programming language out there that makes up for the sloppiness and inability of the person behind the screen.
Naturally, even though you can disregard the templating and resort to idiomatic JS, like one in React, you managed to develop an opinion after not using the features you like.
This just makes no sense honestly. I'm all for people having opinion to the point where you can blatantly say "I hate Vue because I like React more", there's literally no need for justification.
But spewing nonsense just to justify your preference is just bad. Are you a junior dev by any chance?
I've used both extensively and I can recommend Vue over React because React is a pile of mental manure. I never understood React hype, but then again - IT is a fashion business, and when "leaders" invent crap - flies tend to follow.
I can tell you didn't read carefully what I wrote, but that's fine.
Here's what Spotify tells me: "Spotify gives you instant access to millions of songs – from old favorites to the latest hits. Just hit play to stream anything you like."
Where's "but we'll also monitor you and inject whatever code we can, we might allow our customers to do so too, we don't know what it might be but since we wasted $0.003 to acquire you, we need to make at least $5 off of you and we don't really care what happens to your device or if someone breaches our customer and does bad shit to you."
I believe in reciprocity - and the odds are worse at my side if I "freeload" :)
I don't know about the rest, but I really hate when someone makes a fool out of me. I'm a lazy person too, if a service that I like asked me bluntly "hey dude, wanna give us all your info and let us sniff your traffic so we can stick ads in, we're even gonna sell it" - I'd say - sure, you were honest enough, screw it - go ahead, I didn't have to navigate through a wall of text critting me for 9000000 to get that piece of info.
But no. No one behaves like that. Long user agreements, service agreements, catchy call-to-actions on websites that promise wonderland filled with unicorns shitting M&M's and what not just so they get those few bucks out of me...
Oh well, hello foobar2000 my old friend, seems like I'll un-lazy myself just to spite these prying assholes.
It appears that we think about different terms when visualizing what "incompetent" means.
We create languages to tackle different sets of problems, and we want to minimize human error - that part, I believe, we can agree on.
However, if you perform "SELECT * FROM mytable" (table grows indefinitely) and then sort / limit in the language and not database - you're incompetent, you simply lack knowledge and you didn't even think abstractly what can happen by doing so. There's no language out there that can teach you "right tool for the job" or "keep it simple" or "should I do it, maybe there's another way, did someone else have this problem?", no matter what wizard creates it.
We will never weed out incompetent people by creating languages and a language shouldn't cater to a moron.
However, let's prove once more that languages evolve: http://php.net/manual/en/book.ds.php
The "classic" you're referring to is far from something objective. There will always be problems with languages. That's why we have the human factor who is supposed to be intelligent and work around the apparent issues and make the computer do useful work despite apparent tool glitches.
Sadly, we're just creating better idiots who are only getting better at whining.
Guys who maintain Firefox - thank you. I hope I'll join the FF users once more in the near future.
Framework continues to evolve, for the better of course. With the introduction of PHP 7, I believe Laravel will get rid of magic eventually. Meanwhile, we've got tools to help ourselves.
In certain use cases, it literally annihilates Golang for example and leaves node.js way, way, way behind.
Now, ignoring the numbers, there are many things you can do using PHP:
- web applications
- background services
- queue systems
Imagination is the limit (but that applies to any language these days)
There's plenty options to choose from, from web-related frameworks to community provided libraries, even the command line interface received a ton of cool libraries to play with. I can't state that you can do X in PHP but can't do the same in Y, Y being another language. However, frameworks such as Laravel make it trivial to bootstrap a project, create an API, create a nice UI using Vue (Laravel comes with excellent Vue tooling) and deploy the whole thing in a few easy steps to popular hosting providers.
Granted, it's not language specific, there was a huge community effort behind everything PHP related: from standards, to package manager, to tooling, utilities and so on so the ecosystem is quite healthy and progressing.
The nice thing about it, ultimately, is that it's really fast enough and keeps getting faster, with new (useful) language features.
If you're after a tldr version and don't care about the wall of text above:
Strenghts:
- excellent ecosystem http://www.packagist.org, http://www.getcomposer.org
- excellent *nix support, easy installation: https://launchpad.net/~ondrej/+archive/ubuntu/php
- great object oriented model that supports strong typing: http://php.net/oop
- excellent choice of web-app frameworks: https://laravel.com/, https://lumen.laravel.com/, https://symfony.com/
- big choice of extensions that expose additional functionality, such as swoole: https://www.swoole.co.uk/ or zeromq: https://github.com/mkoppanen/php-zmq
- great performance for an interpreted language
- easy scaling due to php-fpm http://php.net/manual/en/install.fpm.php (this has been available for a decade)
Without going into what I've tried and yadda yadda yadda, white noise, my credentials and so on - PHPStorm id the IDE. No Atom / VSCode or whatever can't compare. You get ctrl+click go to definition, you get ssh terminal, you get XDebug integration, it plays with Vue/ES6/React, you get MySQL integration, Vagrant integration, extensions to get VIM bindings and so on. Next to proper keyboard, monitor and mouse - buying PHPStorm is hands down one best money spent when it comes to what I work with every day.
I'm NOT saying "you can't get X with Y editor which is free" - sure, I believe you can, but this thing completely satisfies my every requirement and I don't have to spend time looking for integration extension or whatever. It saved me a ton of time so far, it will do so in future - I approve it, however I don't think anyone's editor "sucks and you should go with PHPStorm". Everyone should go for what they think brings them the best experience / value.
I want to believe this. I want to be hyped. It sounds great. But there's no reproduction scenario. Some claims are also false (php doesn't kill the process to start the processing cycle). Others seem too good to be true - like 40x speedup.
It just smells like "hey, we are cool kids too, look at us, we're advertising using the hype that other kids use!".
If I'm able to reproduce 40x speedup, I'll so gladly eat my words and flame myself.
During registration you receive several pieces of info, such as keyHandle, public key you use to verify future device responses and an attestation certificate so you can verify the device vendor.
The interesting part is this: when you challenge the u2f device to sign AUTHENTICATION request, what it does is keep a counter tied to your appId (the domain where the .js that deals with this is executed) and it produces encoded json which is signed by the device, using an EC private key.
The counter increases every time the device is challenged by that particular appId. The response is signed using the counter and a private key that's on the device (which you can't tamper with).
So, the phishing / mitm should have the value of private key and the moving part (counter) that's tied to a specific appId. That's difficult since it SHOULD do this during enrollment process and every subsequent authentication request.
What's important that not only does it protect against phishing but from replays too. Naturally, the u2f device isn't standalone responsible for this, the verifying server implementation is a crucial part of the process.
Disclaimer: I'm not affiliated by Yubico, but have implemented U2F (the dreaded js part and backend part) in 2015, several months after Chrome 38 has been released, the first version supporting u2f protocol.
Is this yet another marketing ploy where you post something with purposely-misleading title in order to attract traffic? I don't like the fact that word "thousandeyes" got stuck in my head, nor do I like the fact that I got clickbaited. This one is going to my list of "just like every other site since 2015, don't click".
I tried this tool.
It was extremely useful.
I read its source code. I didn't find anything compromising.
I added this tool to my toolbox. Excellent work by Microsoft.
You see how I can have a personal opinion yet use a great tool that helps me?
Could it use improvement? Yes. Does it need it? No.
Simple, fast, does one thing and does it great, has no featuritis and overblown annoying "UX" that current web suffers from.