5 ms·
There's nothing inherently wrong with that password as long as your code isn't vulnerable to SQL injection, which is trivial to do nowadays.
by bqe 11y ago
There's nothing inherently wrong with that password as long as your code isn't vulnerable to SQL injection, which is trivial to do nowadays.
- qb45 11y agoSure SQL injection is trivial to do nowadays; it's always been. I mean, of course I meant this was an SQL injection.
- dragonwriter 11y agoI'm pretty sure GP was saying making sure your code isn't vulnerable to SQL injection is trivial to do nowadays, not that SQL injection is trivial to do.
- rylee 11y agoIt's trivial to not be vulnerable to SQL injection.
- thephyber 11y agoThat's not what "trivial" means. Trivial means the simplest possible example, which in almost every web framework involves passing input as received to the DB driver without knowing its contents and without escaping/sanitizing it. Only by using frameworks and DB drivers correctly (RTFM) is one able to accurately avoid SQLi. I would argue that "using software correctly" is by no means trivial and rarely happens in most systems that have less than NASA quality safeguards. I would agree that most modern frameworks which are adopted by at least a few hundred developers tend to use best practices and a "security by default" mindset, but that's far from saying that "avoiding SQLi is trivial".
- pyre 11y agoThis: > "don't accept ' or 1=1 -- as a password" (the way that it's stated) implies that one should be checking input for possible SQL injection attacks and dropping the request, rather than sanitizing input so that the attack doesn't work, but the password is valid.