Hacker News new | ask | show | jobs
by boring_twenties 2325 days ago
For malfeasance to remain undiscovered you need to be smart and clever.

For the kind of malfeasance that concatenates an SQL query with user input and then shows the whole thing to the user in an error message, you don't need that.