|
|
|
|
|
by Morg
5126 days ago
|
|
I trust noone. except maybe the pgsql guys.
However, imho on the topic of SQL injection, either escaping the escape characters is enough or you should change DBMSs / APIs right away. But really, security without reading sources is blind more or less calculated risk, not security. |
|
What do you do with proprietary/closed source software? What do you do with hardware that is just as capable of poorly implementing security? What about poor decisions that really only become apparent after a security hole is discovered?