Re: Why PHP ?
| From: | Michael Kimsal | Date: | Sat, 09 Dec 2000 23:02:59 +0000 |
| Subject: | Re: Why PHP ? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29507@lists.php.net to get a copy of this message | ||
VBScript is a subset of Visual Basic. Any subset is a limited version
of the complete language, so things that VB has might be missing, yet
'VB' in the name is part of the selling point of ASP. "You already know VB,
so you can just drop into VBScript".
Whether or not that's entirely true is another story. I got out of VB around
1996, so I can't comment specifically on how much functionality from the current
parent might be missing in the baby brother VBScript.
Criticisms of VBScript are hard because there's just not much to it -
much functionality is had through system objects (Server.method(), etc.)
Other criticisms that VBScript doesn't have feature 'X' are always rebutted
with 'there's a COM object from ddd.com you can get, or just build your
own!'. In VB of course, meaning you have to either shell out money
on someone else's object, or shell out money and training on VB
and learn all the intricacies of Windows to build an object to get the
system to go 20% faster.
That criticism holds for PHP as well somewhat. If something's not
there, you can 'build it yourself' - in C. I don't know VB, and I don't know C
-
not well enough to write modules/objects for production use, anyway.
However, on the PHP/Unix side, there are many free/cheap libraries to
do things that cost $ on Windows - even something like GD. I think
you can get GD for Windows now, but hey - try convincing an MS shop
to use a free tool, even if it exists. I've found a few free ASP file upload
utilities (built in to PHP, I might add) but the prevailing attititude at the
MS shops I worked at was 'dude, don't use that - it might be unstable.
Just go to software-artisans and get their's - it's only $50'. $50 across
50 web servers on large production environment adds up. Granted, $2000
on 'extra' licensing, when you've got hundred of thousands in hardware
software is probably not noticed, but it does represent 'nickel and diming' to
death, I think. I'd prefer that extra $ go in my pocket for installation
and customization, not a third party who's making $ off the fact
that ASP doesn't do basic things very well.
We've talked about ASP and VBScript interchangeably. Nearly everyone
equates the two, for pretty good reason, imo. Go to "ASP" support sites -
I'd hazard a guess that over 90% of the content is VBScript-oriented.
Yes, you can use PerlScript, but don't expect to find much support from
fellow developers. There may be small pockets of users, but it's nothing
like the VBScript massive user base out there.
VBScript string handling was/is fairly appalling from a memory usage
standpoint.
A = "hello"
A = A & " there "
A = A & " world"
would create a memory space for A,
then on the next line create a separate memory space for the next version of A,
before replacing it. I'm simplifying some, but we ran some string handling
memory tests last year - for large string handling it was *slow* and
very memory hungry. Boxes with 256 megs at 400mhz machines were
crawling. Apparently this is much better in IIS5/ASP3, but I've not
confirmed it first hand.
This is part of the problem - any criticisms people have will be met with
'but the new version fixes it' - and indeed it might, but the new version will
almost certainly introduce a whole new host of performance issues as
people push it and prod it in ways it wasn't meant to be used. Good or bad?
I dunno, but it'll happen.
Ack - another one. You can't do dynamic includes:
PHP
<? if (blah) { include("blah.php"); } else { include("foo.php"); } ?>
Just CAN NOT be done in ASP2.5. ASP3 introduces a workaround
by introducing server.execute as a server function - you can execute
another ASP script and include the results. End result should normally
be the same, but it's NOT including the second file in the first - they
CAN'T do that, and apparently don't want to, else they'd have done it.
And security - we had a field day putting together http://www.aspsourcecode.com
It's not AS useful now, but there will be new security holes in IIS.
For the record, as of May this year, 1800flowers.com, jcpenney.com,
priceline.com,
and other HUGE names using ASP were all vulnerable to ASP source code
hacks that were documented in January. IIS5 fixes those holes, but who knows
where new ones will be in IIS5? They'll be found. I think I even have a
password
for JCPenney.com someplace. Can't actually get into the servers, but it was
still funny to see. 'desert' or 'vegas' or something like that. 'Best
practice' coding
of not having passwords and database IP addresses are advised, and prevent
some casual snoopers, but I'd say an 'out of the box' NT machine is inherently
less secure as a web server than an out of the box Unix variant. W2000 is
probably more secure, but still is susceptible to source code viewings, tho
not as many variations as NT/IIS4.
This is bashing ASP - not telling you WHY PHP is a better choice.
I guess the simplest answer is that it doesn't suffer the problems listed above.
Defining yourself by pointing out flaws in the others isn't always the best
way to go about it, but it's useful for people that can only think in terms
of ASP/NT/IIS. If that's all they know, speak their language. Point out the
flaws (security can be a big one) - then point out that PHP doesn't suffer
from those flaws.
IIS/ASP is still a formidable combination in many situations - MS has spent
millions making sure it's fast. The eweek article from a few weeks ago
notwithstanding, it's still very fast compared to standard PHP/Apache.
It caches compiled ASP code - it's going to be faster, at least at
repetitive benchmarks, which is what many 'upper managements' look at,
not 'real life' scenarios. And how can they? MS licensing prevents
publishing of performance data. (Oracle and others do too, so it's not just
MS).
I'm ranting here - you've posed the eternal hard question. There are
more anecdotes and reasons in the archives
(http://www.phphelpdes.com/search may help). Bottom line is that
you may not convince people to use it - it's outside their comfort
zone, and people don't base decisions on logic, but emotions.
Emotionally, there is a certain flair to using PHP - it's a bit of the
'underdog', so many here who defend their choice do so emotionally,
not logically. And there's only so far logic can take you.
Tying your cart to MS can be financially rewarding for the short term,
or maybe the long term. Tying your cart to PHP/Open Source/etc
may seem strange, and it may backfire. Only your company can
make the decision for your company in the end.
I hope this helps in some way - I'm available to discuss this further
privately if you wish, or on the list - I don't care, but people may tire
of this topic. Of course, some people tire of 'how do I search in MySQL'
and 'how do I set a cookie' questions too, but they still crop up
every now and then. :)
Jeff Demel wrote:
> We all now that, huh?
>
> Again, WHY does it suck? What's wrong with VBScript? It is VBScript, not
> Visual Basic that ASP uses, but remember you can also use PerlScript,
> JScript or any other language you want (as long as there's a scripting
> module for it). You could probably even use PHP, if you had the desire to
> write your own module. But what's important here, I think, is providing
> specific examples of why one should choose PHP over ASP/VBScript or
> whatever.
>
> So let's get down to nuts and bolts and specific examples.
>
> -Jeff
>
> -----Original Message-----
> From: Kurth Bemis [mailto:kurth@usaexpress.net]
> Sent: Saturday, December 09, 2000 3:38 PM
> To: Jeff Demel; JB; php-general@lists.php.net
> Subject: RE: [PHP] Why PHP ?
>
> At 03:34 PM 12/9/2000 -0600, Jeff Demel wrote:
>
> does anyone ever mention tha ASP isn't a language itself - as php is...ASP
> is a variant of Visual Basic.......and we all know that visual basic sucks
> :-)
>
> ~kurth
>
> >There is nothing in your reply that would convince anyone to use PHP over
> >anything else. The question is "Why PHP?"
> >
> >You say that ASP is limited. Fine. HOW is it limited? In what ways
> >specifically? What does ASP not do that PHP or some other scripting
> >language can? You mention that ASP has performance and stability issues,
> >and that's difficult to accuse a language of, as I'm sure you're well
> aware.
> >Most often those issues are a result of poor coding. However, that's not
> to
> >say that your assertion is wrong, it's just not backed by any evidence.
> >Where are the numbers to prove stability issues, and where are some
> specific
> >examples showing the "limitations" of ASP and how PHP overcomes them. That
> >would be valuable.
> >
> >Paying for support is an interesting argument; however, I think you miss
> the
> >fact that there are tons of free support sites, news groups, and email
> lists
> >for ASP, just as there are for PHP. The monetary downfall of ASP resides
> >more with the outrageous up-front and ongoing costs of the platform than
> >with support.
> >
> >I hope I'm not being too harsh, but I think the question is a really good
> >one, and I would like some legitimate responses with specific and detailed
> >examples. Opinion is a fine thing, but when trying to make a business case
> >for using a programming language and/or environment, specifics are needed.
> >
> >The stance of management folks is almost always that "we'll go with
> >Microsoft, unless you can convince us otherwise." So from the beginning
> >it's a battle. I would really like some good ammunition, and not just more
> >opinions and anecdotes.
> >
> >-Jeff
> >
==========================
Michael Kimsal
http://www.tapinternet.com
PHP Training courses
http://www.tapinternet.com/php
734-480-9961