Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My current employer has asked me to forget about "SQL Injection `problems`" and told me to focus on the deadline. sigh


This came up in our engineering ethics class in college. Suppose you said "No, that is unethical / professional irresponsible / etc." or its effective-but-weasley younger brother "Please document that request in writing."?


Don't worry, I ignored his request. :)


Submit an exploit anonymously somewhere where it will get published. Obviously, don't indicate that you're an employee. A big benefit of full disclosure is that it doesn't allow companies to sit around and ignore security problems without facing serious liability risks at the very least.


I've never used any library to communicate with a database that made safe code harder to write than unsafe code, so I don't see how this will be an issue.


It's not difficult to avoid, is it? Sanitize input and use parameterized statements. I'd take longer to not do those things, personally.


"`problems`" in scary quotes. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: