3 ms·
You would think that using prepared statements would be the norm by now, but I'm not so sure anymore. Today as I recovered my password from website of a multi-n
by tommi 14y ago
You would think that using prepared statements would be the norm by now, but I'm not so sure anymore. Today as I recovered my password from website of a multi-national gym, I got it in plain text. There are some crazy shit out there so treat every service like it will be hacked some day.
- kijin 14y agoKeeping passwords in plain text has nothing to do with not using prepared statements. There may be a correlation between the two types of stupidity, though.
- archivator 14y agoReport them to http://plaintextoffenders.com/ http://plaintextoffenders.com/ ;)
- DrJokepu 14y agoThis is not relevant to SQLite, but depending on your table structure, the constraints, your data, your query and the phase of the moon, some database systems (Oracle and PostgreSQL come to mind) can generate much better query plans if all the values are available when the query is planned. I still wouldn't recommend anyone to concatenate the (escaped) query parameters right into the query text unless they really know what you're doing.
- electrum 14y agoThis problem seems to be fixed in recent versions of Oracle: https://blogs.oracle.com/optimizer/entry/explain_adaptive_cursor_sharing_behavior_with_cursor_sharing_similar_and_force https://blogs.oracle.com/optimizer/entry/explain_adaptive_cu...