3 ms·
I do agree here. As I mentioned the first version of the class was both security and programming. The projects were intermingled giving students A great overvie
by ikhare 17y ago
I do agree here. As I mentioned the first version of the class was both security and programming. The projects were intermingled giving students A great overview. Unfortunately in the 10 weeks of the quarter it's hard to cover both in great depth giving only a cursory understanding of both. There is a separate great intro to security class cs155 (which I also TAed). I believe the professors were thinking of creating a class entirely on web security at some point.
I will add however that as security gets baked into frameworks, students are not at least pickng up bad habbits.
Wow this is hard to write on an iPhone :-)
- IgorPartola 17y agoWell, I can certainly appreciate a separate security based course. However, my point that preventing SQL injections should not be viewed as security. Just like you shouldn't write code that takes as input other code and blindly runs it on the server; or serves any file on the server without any sort of checks. Using prepared statements, or if you can't, at least manually escaping user data, is part of writing functional code. A program that does not do this is not functional and as much as writing down an example that shows how to do it breeds bad code.