3 ms·
That’s the kind of thing you say to ship a product to market, to eschew a non-critical feature. Parametrized Queries for a SQL library are a critical “do not s
by sqliwtf 5y ago
That’s the kind of thing you say to ship a product to market, to eschew a non-critical feature.
Parametrized Queries for a SQL library are a critical “do not ship without” feature. You do not lie and tell your user you have a safe product causing them to have a compromised system.
I hope to God you are not creating production systems anywhere.
- jsiaajdsdaa 5y agoImagine working on a flight controlller that has functions that produce the wrong values for flight control! "it's ok, something is better than nothing" is not true!
- tragictrash 5y agoWe had a candidate with 'wrote dynamic sql' listed under a job he held previously. They also couldn't answer the question 'how do you prevent a sql injection attack'. He had something like 5 years of experience. I don't understand how anyone but the greenest of devs doesn't comprehend the importance of these kind of things. But alas, I see it everywhere, including the comment you are responding to.
- papercrane 5y agoI had a similar candidate a couple weeks ago. Their CV made a big deal about a dynamic SQL framework they wrote for a previous job, but they just gave me a blank look when I asked how they mitigated SQL injection attacks. I ask about SQL injection pretty regularly, and it's scary how many devs don't seem to even know what it is.
- DaiPlusPlus 5y ago> I ask about SQL injection pretty regularly, and it's scary how many devs don't seem to even know what it is. That's either a good thing: because they grew-up with database libraries designed to encourage, if not force, the use of parameterized queries, so it was never a problem for them. ...or it's a bad thing, because they grew-up in the early-days of PHP 4x, learning from PHP/MySQL tutorials written by people who'd today be considered utterly unqualified to speak at length about programming: the kinds of things that only happen when the blind were leading the blindfolded: nightmares like actively encouraging concatenating $_GET values directly into mysql_query() strings because it means having less variables, and less variables means better performance (right?!) - and they never learned otherwise. ----- I have a pet theory that people who got started with PHP in the 2000s who are still working today are so burned from their earlier experiences that they're now the most detail-oriented and best-practices-following programmers around, regardless of the language they use today - while the people who never experienced hardship (to the extent that having to use PHP is a hardship...) become complacent, and our ever-increasing reliance on unvetted external dependencies (in all language ecosystems, imo) is going to end badly. Or not. No idea, honestly!
- Aeolun 5y ago> I hope to God you are not creating production systems anywhere. Good luck building production systems without compromises. Also, I think everyone would appreciate it if you didn’t hurl personal insults about. This aint Reddit.