Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And this is why you shouldn't use ORMs. Magic blackboxes always bite you in the ass eventually.


Yes I would definitely trust an application much more if each and every one of its SQL queries was lovingly hand crafted by a human being.

Because if there's one thing computers are truly bad at, it's transforming high-level things into lower-level things.


If there is one thing computers are in fact bad at, it is understanding intentions, an ORM in many cases is a translation of an intention from one level to another.

In my experience lovingly hand-crafted SQL for your application does not take as long as you think it will and does not subject you to the interpretations of an intermediary. ORMs are useful but there is something to be said for writing the SQL you want to do what you want with a database.


As an expert on security, what makes you think that in 2013 every webapp out there should still be backed by SQL and running SQL queries?

I mean is SQL something inherently so secure that all webapp devs should use?

If you're not a DB expert, what would be your rationale for using SQL instead of other alternatives?

It's not like if every website out there was using SQL. Heck, not even all sites are using OO languages.

So while I agree that an ORM is nice if you're stuck that particular Java/C# + SQL hell I fail to see how exactly OP did imply that he recommended objects and SQL...

He said ORM sucked. Not that he was using "objects" and SQL...


SQL is not intrinsically insecure.


Come on, the parent comment more or less implied that ORMs are bad, not that he was using flat files or a non-relational DB (many of which are often wrapped in ORMs anyway).


Until someone gets the bright idea to push all your complex queries down into stored procedures. Then it becomes a mess, the dba quits, you go back to an ORM, have some weird issue like this Rails bug happen, then someone says, "Hey, what about using raw SQL...we'll just make the gnarly bits into stored procedures..."

Circle of life, man.


Is this sarcasm?


Yeah, why use SQL or language bindings, just write into the B-trees themselves.


Because there's no middle ground between ORMs and packing your own varints into registers.


I'm not the one that implied all blackboxes are bad.



I'm so excited to see this posted everywhere. It will be just like reddit where everyone makes a loose connection to what they think is a logical fallacy and then just shouts that instead of taking time to actually put thought into a post. And I can just imagine the smugness that goes along with posting that.

He implied black boxes are bad. ORMs are black boxes, so are dozens of things that programmers use every day. I understand some of the arguments about why ORMs are bad, but it hardly stems purely from them being a black box.

BTW: My post is not an example of a slippery slope fallacy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: