Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're prohibiting valid letters to protect your database because you didn't parametrize your queries, you're solving the problem from the wrong end


This is all well and good until the company looses real money becaus some other system you are interfacing with got compromised because of your attitude and fingers start being pointed. Defense in depth is a thing.


There might be more than just 2 ends. And some of them may not be fixable by you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: