|
|
|
|
|
by user15672
3324 days ago
|
|
> Finally, ANY type of input sanitization is wrong way to do security, and should be employed only as an absolute last resort. Ok, that's just plain wrong and absolutely wreckless advice. Everything from software development 101 classes to OWASP data validation can call you on that. If you don't understand why you're wrong, please, please, please stop developing software now until you can understand it. |
|
This is a prime example of the Robustness Principle. https://en.wikipedia.org/wiki/Robustness_principle