3 ms·
There is no other word that isn't confusing. If you refuse to actually do some cursory research into something before implementing it, you're going to get the s
by awda 12y ago
There is no other word that isn't confusing. If you refuse to actually do some cursory research into something before implementing it, you're going to get the stupid delete-is-sanitization stuff the author describes.
"Doctor, it hurts when I do this." Don't do that!
- mfisher87 12y agoExcept it looks like everyone's confused and there's a lot of misinformation or high signal-to-noise ratio already. My google search "Input sanitization" yielded these first 2 results http://en.wikipedia.org/wiki/Secure_input_and_output_handling http://en.wikipedia.org/wiki/Secure_input_and_output_handlin... 2nd page (or more with a lesser screen), under "other solutions," this is the only line about parameterization: "In particular, to prevent SQL injection, parameterized queries (also known as prepared statements and bind variables) are excellent for improving security while also improving code clarity and performance." Everything else is about filtering, blacklisting, whitelisting, escaping. http://www.esecurityplanet.com/browser-security/prevent-web-attacks-using-input-sanitization.html http://www.esecurityplanet.com/browser-security/prevent-web-... Discusses filtering as solution to HTML injection. Lastly discusses SQL injection, first recommending mysql_real_escape_string(), then in the second paragraph linking to another article about parameterization. It's not, to an inexperienced developer (this is the web remember?), a clear-cut best practice from just "cursory research". It's a popular tech joke with obvious but non-optimal solutions.
- awda 12y agohttps://www.google.com/search?q=input+containerization https://www.google.com/search?q=input+containerization What does the inexperienced developer learn from the new search terms? I don't know why magically using different, non-standard words would prevent a developer from being inexperienced.
- mfisher87 12y agoWhy do you think that? The idea isn't to tell new developers to search for content that doesn't exist. The idea is to teach better solutions, a small part of which is using correct descriptive language when naming things. "I don't know why magically using different, non-standard words would prevent a developer from being inexperienced." It's really hard to give any response to this sort of flawless logic...