Thought you guys might enjoy this, I am trying to get any info about a CMS(?) that a client wants to use, I would greatly prefer to use Drupal, in order to do this i have to give reasons why Drupal is better. Anyways, I asked the company that makes this cms (PHPYellow) to provide any reasons why i would want to use it for phone listings instead of Drupal, I was provided with the following answer:
"CMS's like Drupal will never be able to do as good as job
as a dedicated application like phpYellow which is designed from the ground up to
serve yellow pages. Also, Drupal announces security vulnerabilities on its home
page:
phpYellow apparently has much better security."
Yes, apparently. My favorite part is the "Content Managements Systems's", anyways I am pretty glad Drupal has a community of users that understand its important to actually check and maintain security bulletins unlike this wackjob.
Comments
I just got this response in
I just got this response in regards to why PHPYellow is better then Drupal..
"Hello Leo,
Here is what you get with phpYellow: http://phpyellow.com/demo/index.php
Here is what you get with Drupal: http://drupal.org/"
What? Is this really happening or is this guy just screwing with me?
Sounds like the guy who runs
Sounds like the guy who runs phpyellow.com is a nutjob. It looks crap anyway.
Use Drupal.
As for the posting security vulnerabilities on the front page, I dont think thats quite correct. They post new releases which fix security vulnerabilities on the front page. Its the whole open source vs closed source issue. Security through obscurity is not security at all.
Very true... Security
Very true... Security through obscurity is not security at all.
Security
Agreed.
Drupal now has a very good security record (especially for anything written in PHP). But before Drupal 4.5 or so you couldn't really tell how good Drupal was with security - the smaller userbase and lack of scrutiny meant that most security problems might not come to light. For less well known software, a lack of public security patches doesn't mean there aren't any problems.
In the 4.6 era, Drupal came under a lot more scrutiny (XMLRPC anyone?) and a dedicated security team was set up and a lot of problems were fixed "out in the open" and set the standard for how Drupal deals with issues - ie quickly and publically.
With this security infrastructure well established and the new Forms API helping out, 4.7 ended having about half the updates that 4.6 had. And now, Drupal 5 has only required one update since its release and that was 6 months ago - 4.7s last update was 6 months ago too. Drupal now has a very good track record with security.
Hehe I couldn't possibly comment, but I did love the Australian flag on this page:
http://phpyellow.com/examples.php
http://i15.tinypic.com/4mmfr81 (screenshot)
(Note: it's not the Australian flag)
--
Anton
New to Drupal? | Troubleshooting FAQ
Example knowledge base built with Drupal
Security
Results in the past are no guarantee for the future :)
Assessing the security of an application is quite difficult without doing a code review. If you've charted up 10 vulnerabilities after 2 minutes of review or if you notice certain API elements are missing (output filtering, anti-SQL injection API) the verdict is easy; otherwise; very difficult.
The amount of advisories is also not an easy measure for security.
Last but not least; Just having a security team hanging around drinking beer and eating pizza's till the midst of night doesn't make an app. magically more secure; one just hopes there's a more or less coordinated response when an issue is discovered.
So let's not pride ourselves too much.
--
The Manual | Troubleshooting FAQ | Tips for posting | How to report a security issue.
Sure
While I agree that number of advisories isn't an easy measure and can be useless when comparing different projects to each other, I don't think it's a stretch to claim that Drupal 5 is more secure than 4.6 was. The APIs have improved a lot and the developers take security very seriously.
Also I think that the Drupal userbase is now big enough and there are enough bad guys (spammers mostly) constantly hammering Drupal sites that any security problems would make themselves known pretty quickly. Even with Drupals smaller userbase and lower profile back in the 4.5/4.6 days some problems still made quite a bit of noise.
I am glad to see you aren't getting complacent though :)
--
Anton
New to Drupal? | Troubleshooting FAQ
Example knowledge base built with Drupal
Sheep
Haha, thats the New Zealand flag.
The critique was false
Hello Leotemp,
Yes, drupal.org indeed looks very "raw". And the site the guy named to you as an example does not look any better to me - very poor, as if made in mid 80th =)
BUT, THE TRUTH IS...
You CAN build cool sites with Drupal. In fact, Drupal is the MOST flexible CMS for cool designs. I am a relatively young Drupal designer/developer, I have spent a year designing and coding for SpryDev. In time I came to realize that Drupal is flexible beyound any of my expectation. It can be very beautiful, and it is only limited by the time you have to complete the project =)
You may view the library of web designs at SpryDev and see the path that we have been following in this direction. None are perfect of course, but I hope it will provide some arguement for Drupal and the beauty that it can be.
http://sprydev.com/design-gallery
I am now working a lot in trying to incorporate icons and jQuesry for effects in Drupal pages, but this happens in only free time of course, fo rit takes a lot of experimentation with coding ;)
In my opinion a fact that
In my opinion a fact that somebody publishes information of security vulnerabilities on a web page is a mater of profesionalizm. Every application has bugs. Especially a big ones. It is better to inform and release patches.
Some simple dedicated applications migh be better for simple highly specialized tasks.
But on the other hand, if you have dedicated software, it is usually hard to introduce new functionalities.
My client has a big commercial CMS and he is willing to change it for drupal for few reasons:
-he is not tied to one single vendor
-he was astonished when I told him about functionalities we can create
-his system lacks many things - and the company would take a lot to introduce them, or is not capable of doing this
-system made by few people, even best of breed, cannot match the one that has hundreds of developpers and thousands of testers. Drupal is just much safer and stable.
best regards,
Pawel Gawlowski
e-solutions.pl
drupal.pl
Thanks for the input, I
Thanks for the input, I generally agree and It makes me sad that there are people out there just nailing business' left and right with terrible products, Is there some kind of list that serves as a warning to less savvy internet consumers, like say a place one could go to get recommendations for real vendors and perhaps ones to avoid.
Open vs Closed source and Marketing
I like to contibute to this conversations from a marketing point of view.
I think is speaks for Drupal's integrity to post security related toppics on the front page. The way it is being done however can be rejecting to non-techies and newbies. Note: majorety of decession makers in non-technical! I think we can learn from the Joomla way of communicating things a bit. Not in the way of hiding security anouncements in buzzwords, but in a more politic and marketing correct manner. It shouldn't be necessary to shout to first time visitors on the first line of the front page "...a security vulnerability. Upgrading your existing Drupal sites is strongly recommended..." 5 MONTHS after the fix is released!!
Yes, inform the community correctly.
No, do not unnecessary chase away ignorant visitors looking for information.
If not necessary do not provide information that can be used to discredit Drupal (as in the above case...)
Suggestion:
Place a large something that shouts "New to Drupal" on the frontpage. Link it to:
Simple, attractive website with:
-(Flash)Demo, not plain (not so pretty...) Drupal, but for example enhanced with WYSIWYG editing, corporate theme and functionality everybody looks for preconfigured.
-Plain explanation of Drupal capabilities, maybe by use of cases.
-Some testimonials of Drupal site owners in corporate, public and nonprofit sectors.
-Make it buzzword compliant, it's stupid, but it helps to convince decision makers.
-De NOT make it a community site, or it will be polluted with well-meaned posts like mine here ;)
Drupal.org is no website to show to your supervisor or corporate client like: Look at this, this is the CMS we should use for our project/company! Nor is the opensourcecms.com demo very suitable for that.
I think we should provide that.
I'm not only suggesting this, we are willing to help providing this if it turns out to be a widely supported idea.
Just my 2...
Kees
Webbased applicaties, content management systemen, websites, webdesign
phpYellow Exceptionally Reliable for Web Business Directories
A LAMP application expressly made for delivering Yellow Pages
leotemp implies that phpYellow is a Content Management System(CMS). phpYellow is not, has never been held out to be, nor is, a CMS. phpYellow is a LAMP application expressly made for delivering yellow page content. While phpYellow Pro Edition has many features and is capable of handling images, videos, text, email, urls and other web content this is in support of serving yellow pages. phpYellow has been online since 1996 making it an exceptionally reliable and stable platform for web business directories.
It is true that phpYellow Lite Edition is open source and freely downloadable on Globalissa.com:
http://www.globalissa.com
Complete details about phpYellow Pro Edition TM are available on the phpYellow home page here:
http://phpyellow.com
Helping the Open Source Community
Globalissa.com also offers other freeware, including admin-login-only which is a single user authentication software product you can put on your own website to protect sensitive webpages. Admin-login-only is offered with an LGPL license. The first 'L' in LGPL means you can use admin-login-only for commercial use free of charge. This is way beyond open source, this allows you to sell admin-login-only!
Globalissa offers admin-login-only, EasySQL, as well as didactic articles on our website in the true spirit of giving something back to the open source community.
Pointless Discourse
With respect to "in order to do this i have to give reasons why Drupal is better" ... obviously the writer (leotemp) has already made up their mind, so, if you have already made up your mind then why drag a third party into a pointless discourse? Its easy to shoot your mouth off on your favorite board with your peers in automatic peer agreement. Its another matter to obtain the correct facts, then act on those facts as an reasoning human being.
What has leotemp done to help open source?
Facts are phpYellow is an open source resource with superlative and extensive features however phpYellow is not a CMS, despite what leotemp says.
BTW leotemp, what have YOU done to help the open source community?
Um was it you that said
Um was it you that said this:
and this:
Leo wanted a second opinion, because your replies to his questions were very biased, incorrect and rude. He didn't criticize your product, but the way you answered his questions.
BTW go and promote your products elsewhere, we dont want your spam.
Pointless Discourse
Actually globalissa a client had asked and expressed general concerns as well as wishes to use your product, that is why I contacted you and asked very straight forward questions which you diliberatly side stepped in an obvious attempt to blur the issue at hand. If you had answered with anything even something along the lines of "support" I would have told my client that and they may well have chosen your product, we know your designs don't reflect the final product you sell and we were never judging it based on graphic "clarity". Instead of answering my questions you litterally implied that somehow drupal is insecure because they have a mailing list to alert users of security problems. You knew what you were doing was misleading but you did it anyways, so i asked you:
"Do you have any data you could provide me that could back up what your saying such as performance/core feature comparisons and or security check s that phpyellow has endured and passed?"
Once again, another honest straight forward question that I needed an honest answer for so i could make a real decision, your response was to hand me 2 urls I obviously already had which is assinine since you list maybe 5 features that even Wordpress has. You then ask every sales hook question you can think of:
"What kind of yellowpage directory are you planning? Geographic scope? Market?
Categories? When are u going to launch? What is your domain name? etc etc?"
It's obvious in my opinion you don't have my best interest in mind and I terminated our communications at that time, don't come here and vent because you failed at luring me into your lame product stream that includes paying 20 bucks for things like country buttons that look like rear.
As far as what I do for the open source community is I come here every day on my time off and answer any questions my new to the scene ass can answer. I am building things for this community and I do love my new home and it's laughable that after how you handled your self you come here and complain. I wonder how my complaints would be handled by you after you sold me a crapware system that won't handle my clients needs because you purposefully dodged my real questions?
Creepy Spooky
I found a Better Business Bureau entry referring to Global I.S. S.A., the "company" that makes phpYellow, and it puts the company in Vancouver, Washington, although the company "cannot be located" due to its address being a PO Box and all it's phones on record disconnected, adding that "[i]f you have an unresolved dispute with this company you may wish to seek legal advice."
So I looked for a business record in Washington. Doesn't exist. Maybe the biz really is closed or maybe it's actually in Oregon. I searched in Oregon. Not there either. I did a Whois lookup on the domains which places the business at a bogus looking PO Box in Panama, Pennsylvania. Fine. I look in Pennsylvania. No record of Global ISSA there either. So I trace his IP and it turns up Vancouver, alright. Vancouver, British Columbia. Unfortunately trying to find a searchable biz directory in Canada is like asking for an iPhone in Amish country so the trail ends there.
Typically, trusted businesses do not make themselves difficult to find. The fact that there is no contact information on phpYellow.com or GlobalISSA.com/net via snail mail, telephone or fax is suspicious, to say the least. What one does find is a service request form requesting your FTP and web host admin usernames and passwords which is downright scary. Why is this information required?
Global ISSA answers that question in response to a complaint saying "No software supplier can do a web server install without access to the web server. Apparently the customer has not figured this out yet." And if the software considered deficient in some way like, oh I dunno, search features? Their answer is: "We recommend Google for those users - such as the reviewer - who do now [sic] know how to use a web browser or do not know how to perform a basic web search." Nice. With customer service and feedback like this who needs suicide hotlines?
And with this attitude, phpYellow is touted as open source? Who are the contributing members and what, pray tell, is their cut of the profits? And what happens when a third party discovers a vulnerability in their software? Answer: "The vulnerability you refer to has been resolved. For security we do not release the nature of the solution/s." Well, what is a customer supposed to do then? Upgrade? Disable a feature? Oh, right ... if I don't think about it then it will go away. Shhhhhh ... mums the word then.
I haven't used phpYellow but between obscurity of the company, their almost cult-like paranoia about criticism (constructive or otherwise) and stellar reviews like "I ended up purchasing phpYellow for a Chamber of Commerce client of mine and had to customize the whole thing such that it barely resembles the original." [source] I would personally and professionally recommend against it.
That's my two cents. Hopefully it saves some other poor suckers a lot more than that.
so brutal.
so brutal.
As much as I love Drupal,
As much as I love Drupal, I've always appreciated the friendly attitude portrayed by the community on drupal.org. I don't know anything about phpYellow, but perhaps the creator will have a better attitude about Drupal if he is greeted warmly by our community as I was last year when I discovered Drupal.
=-=
why would the commuinty warmly welcome an individual who A) isn't part of the community and B) who is making blanket security statements about drupal in a way to try and get others to use his product over drupal ?
just doesn't make sense.
If one can't take the heat they shouldn't start the fire : )
_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )
I doubt he intended for his
I doubt he intended for his remarks to be taken into a public forum such as this. I can only imagine he'll eventually see this discussion after googling his company name. I would only wish for him to be interested in Drupal, thus I feel it is important to extend a warm welcome. Maybe he'll abandon his efforts and focus on making Drupal modules. ;)
I guess I should add that
I guess I should add that seeing this thread has just clouded my perspective on what Drupal is/was when I found it last year. I was happy to find a humble, drama-free community that wasn't bad-mouthing other products for whatever reason.
=-=
seems to me phpyellow was the start of the badmouthing by insinuating that Drupal security is lax because they make security bulletins public.
That aside though, this thread is months old. It hadn't been commented on since July until you came along to drag it back to the top of the forums. Thus adding 2 more cents a post that was in the drupal forums graveyard already. Which would have left it "drama free".
For the record: The phpyellow people have already seen this thread per this comment:
http://drupal.org/node/161655#comment-255462
I've always found it best to let sleeping dogs (old forum posts) lie not poke them with a stick to see if they wake up. ; )
Drupal is a vast community of users. With those users comes a vast array of personalities. Letting one (or a few) forum posts or users cloud your perspective of an entire community is overly judgemental. One person, One forum post does not a community make.
_____________________________________________________________________
My posts & comments are usually dripping with sarcasm.
If you ask nicely I'll give you a towel : )
Only trying to be friendly.
Only trying to be friendly. I have no qualms with the Drupal community, I only thought the thread should end on a happy note instead of a negative one.