Hacker News new | ask | show | jobs
by ericbarrett 630 days ago
The good ol’ “Tell me you store passwords as plaintext without telling me you store passwords as plaintext”

The other message I get from sites like this is, “Our developers have no idea how to escape SQL parameters even though this has been standard since the 90s [80s? 70s?!] so we just do “‘“ + password + “‘“ “