3 ms·
I don't do webapps, but I'm sure everyone's vulnerable somewhere, if they do. I just dislike the whole "upvote for x" comment that dredges up from Reddit. 'Ju
by upgrayedd 16y ago
I don't do webapps, but I'm sure everyone's vulnerable somewhere, if they do.
I just dislike the whole "upvote for x" comment that dredges up from Reddit.
'Just lowers the signal-to-noise ratio, and I hate to see things like that creep up on HN.
- uxp 16y agoI wrote an iPhone app with a sqlite backend that was vulnerable to SQLi. Don't think you aren't vulnerable even if your application doesn't touch the internet.
- upgrayedd 16y agoSorry, I just don't do any apps that touch the internet...just some programming for fun on the side. The only thing that I've written that could be applied to this is our POS system at the restaurant I work at as a dishwasher and cleaner for. It's in Django though, and the Django project takes care of most issues with that...not that they're really priority #1 security-wise...
- elliottcarlson 16y agoYou should never assume that your framework of choice does everything for you. This is by all means no shot at Django, but just in general, always assume what you are working with is insecure and full of bugs - and then account for that - if your framework/programming language of choice accounts for additional things - great.
- jarrett 16y agoBut does this mean, for example, that you should escape inputs yourself before passing them off to the framework, which is then ostensibly going to escape them again? I think a better approach is to verify that the framework is correct. You can do this experimentally, by writing unit tests, or by reading and running the unit tests of the framework itself.
- elliottcarlson 16y agoIf you assume the framework is correct, and then you update, migrate, whatnot, can you still be sure the framework is correct, or hasn't broken. If you can ensure your own code is good, then you are ahead of the game in such a situation.
- elliottcarlson 16y agoI don't complain about down votes - but it actually shocks me to think someone felt that my statement was counterintuitive to this thread and didn't offer anything possibly insightful. I think that it is irresponsible to assume third party code is safe - or will remain safe. If you feel that that is overly cautious so be it - but I rather be safe than sorry. But I guess that is just my opinion.