Re: Why PHP ?

From: Date: Sat, 09 Dec 2000 23:02:59 +0000
Subject: Re: Why PHP ?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29507@lists.php.net to get a copy of this message
VBScript is a subset of Visual Basic. Any subset is a limited version of the complete language, so things that VB has might be missing, yet 'VB' in the name is part of the selling point of ASP. "You already know VB, so you can just drop into VBScript". Whether or not that's entirely true is another story. I got out of VB around 1996, so I can't comment specifically on how much functionality from the current parent might be missing in the baby brother VBScript. Criticisms of VBScript are hard because there's just not much to it - much functionality is had through system objects (Server.method(), etc.) Other criticisms that VBScript doesn't have feature 'X' are always rebutted with 'there's a COM object from ddd.com you can get, or just build your own!'. In VB of course, meaning you have to either shell out money on someone else's object, or shell out money and training on VB and learn all the intricacies of Windows to build an object to get the system to go 20% faster. That criticism holds for PHP as well somewhat. If something's not there, you can 'build it yourself' - in C. I don't know VB, and I don't know C - not well enough to write modules/objects for production use, anyway. However, on the PHP/Unix side, there are many free/cheap libraries to do things that cost $ on Windows - even something like GD. I think you can get GD for Windows now, but hey - try convincing an MS shop to use a free tool, even if it exists. I've found a few free ASP file upload utilities (built in to PHP, I might add) but the prevailing attititude at the MS shops I worked at was 'dude, don't use that - it might be unstable. Just go to software-artisans and get their's - it's only $50'. $50 across 50 web servers on large production environment adds up. Granted, $2000 on 'extra' licensing, when you've got hundred of thousands in hardware software is probably not noticed, but it does represent 'nickel and diming' to death, I think. I'd prefer that extra $ go in my pocket for installation and customization, not a third party who's making $ off the fact that ASP doesn't do basic things very well. We've talked about ASP and VBScript interchangeably. Nearly everyone equates the two, for pretty good reason, imo. Go to "ASP" support sites - I'd hazard a guess that over 90% of the content is VBScript-oriented. Yes, you can use PerlScript, but don't expect to find much support from fellow developers. There may be small pockets of users, but it's nothing like the VBScript massive user base out there. VBScript string handling was/is fairly appalling from a memory usage standpoint. A = "hello" A = A & " there " A = A & " world" would create a memory space for A, then on the next line create a separate memory space for the next version of A, before replacing it. I'm simplifying some, but we ran some string handling memory tests last year - for large string handling it was *slow* and very memory hungry. Boxes with 256 megs at 400mhz machines were crawling. Apparently this is much better in IIS5/ASP3, but I've not confirmed it first hand. This is part of the problem - any criticisms people have will be met with 'but the new version fixes it' - and indeed it might, but the new version will almost certainly introduce a whole new host of performance issues as people push it and prod it in ways it wasn't meant to be used. Good or bad? I dunno, but it'll happen. Ack - another one. You can't do dynamic includes: PHP <? if (blah) { include("blah.php"); } else { include("foo.php"); } ?> Just CAN NOT be done in ASP2.5. ASP3 introduces a workaround by introducing server.execute as a server function - you can execute another ASP script and include the results. End result should normally be the same, but it's NOT including the second file in the first - they CAN'T do that, and apparently don't want to, else they'd have done it. And security - we had a field day putting together http://www.aspsourcecode.com It's not AS useful now, but there will be new security holes in IIS. For the record, as of May this year, 1800flowers.com, jcpenney.com, priceline.com, and other HUGE names using ASP were all vulnerable to ASP source code hacks that were documented in January. IIS5 fixes those holes, but who knows where new ones will be in IIS5? They'll be found. I think I even have a password for JCPenney.com someplace. Can't actually get into the servers, but it was still funny to see. 'desert' or 'vegas' or something like that. 'Best practice' coding of not having passwords and database IP addresses are advised, and prevent some casual snoopers, but I'd say an 'out of the box' NT machine is inherently less secure as a web server than an out of the box Unix variant. W2000 is probably more secure, but still is susceptible to source code viewings, tho not as many variations as NT/IIS4. This is bashing ASP - not telling you WHY PHP is a better choice. I guess the simplest answer is that it doesn't suffer the problems listed above. Defining yourself by pointing out flaws in the others isn't always the best way to go about it, but it's useful for people that can only think in terms of ASP/NT/IIS. If that's all they know, speak their language. Point out the flaws (security can be a big one) - then point out that PHP doesn't suffer from those flaws. IIS/ASP is still a formidable combination in many situations - MS has spent millions making sure it's fast. The eweek article from a few weeks ago notwithstanding, it's still very fast compared to standard PHP/Apache. It caches compiled ASP code - it's going to be faster, at least at repetitive benchmarks, which is what many 'upper managements' look at, not 'real life' scenarios. And how can they? MS licensing prevents publishing of performance data. (Oracle and others do too, so it's not just MS). I'm ranting here - you've posed the eternal hard question. There are more anecdotes and reasons in the archives (http://www.phphelpdes.com/search may help). Bottom line is that you may not convince people to use it - it's outside their comfort zone, and people don't base decisions on logic, but emotions. Emotionally, there is a certain flair to using PHP - it's a bit of the 'underdog', so many here who defend their choice do so emotionally, not logically. And there's only so far logic can take you. Tying your cart to MS can be financially rewarding for the short term, or maybe the long term. Tying your cart to PHP/Open Source/etc may seem strange, and it may backfire. Only your company can make the decision for your company in the end. I hope this helps in some way - I'm available to discuss this further privately if you wish, or on the list - I don't care, but people may tire of this topic. Of course, some people tire of 'how do I search in MySQL' and 'how do I set a cookie' questions too, but they still crop up every now and then. :) Jeff Demel wrote: > We all now that, huh? > > Again, WHY does it suck? What's wrong with VBScript? It is VBScript, not > Visual Basic that ASP uses, but remember you can also use PerlScript, > JScript or any other language you want (as long as there's a scripting > module for it). You could probably even use PHP, if you had the desire to > write your own module. But what's important here, I think, is providing > specific examples of why one should choose PHP over ASP/VBScript or > whatever. > > So let's get down to nuts and bolts and specific examples. > > -Jeff > > -----Original Message----- > From: Kurth Bemis [mailto:kurth@usaexpress.net] > Sent: Saturday, December 09, 2000 3:38 PM > To: Jeff Demel; JB; php-general@lists.php.net > Subject: RE: [PHP] Why PHP ? > > At 03:34 PM 12/9/2000 -0600, Jeff Demel wrote: > > does anyone ever mention tha ASP isn't a language itself - as php is...ASP > is a variant of Visual Basic.......and we all know that visual basic sucks > :-) > > ~kurth > > >There is nothing in your reply that would convince anyone to use PHP over > >anything else. The question is "Why PHP?" > > > >You say that ASP is limited. Fine. HOW is it limited? In what ways > >specifically? What does ASP not do that PHP or some other scripting > >language can? You mention that ASP has performance and stability issues, > >and that's difficult to accuse a language of, as I'm sure you're well > aware. > >Most often those issues are a result of poor coding. However, that's not > to > >say that your assertion is wrong, it's just not backed by any evidence. > >Where are the numbers to prove stability issues, and where are some > specific > >examples showing the "limitations" of ASP and how PHP overcomes them. That > >would be valuable. > > > >Paying for support is an interesting argument; however, I think you miss > the > >fact that there are tons of free support sites, news groups, and email > lists > >for ASP, just as there are for PHP. The monetary downfall of ASP resides > >more with the outrageous up-front and ongoing costs of the platform than > >with support. > > > >I hope I'm not being too harsh, but I think the question is a really good > >one, and I would like some legitimate responses with specific and detailed > >examples. Opinion is a fine thing, but when trying to make a business case > >for using a programming language and/or environment, specifics are needed. > > > >The stance of management folks is almost always that "we'll go with > >Microsoft, unless you can convince us otherwise." So from the beginning > >it's a battle. I would really like some good ammunition, and not just more > >opinions and anecdotes. > > > >-Jeff > > ========================== Michael Kimsal http://www.tapinternet.com PHP Training courses http://www.tapinternet.com/php 734-480-9961

« previous php.general (#29507) next »