Hacker News new | ask | show | jobs
by userbinator 346 days ago
he'd simply learned by rote

That's a common problem. A lot of people don't realise that if you accept user input, you can get every single byte and sequence of bytes possible. Validating that a parameter is an integer ([0-9]+) is even easier than escaping.

his job title is "senior developer".

Likely that's purely because of how long he's worked there, not how much he actually knows.