|
|
|
|
|
by closeparen
3521 days ago
|
|
>you never, ever, trust anything the client sends. The author likely wrote code that correctly validates "for all security questions a correct answer is given" and just forgot about the part where "for-all propositions are trivially true of the empty set." It's easy to read a for loop for what it's intended as - a loop - and not think about "what if we never enter it at all?" |
|