|
|
|
|
|
by BobbyTables2
237 days ago
|
|
The developer is too stupid to define the threat model — they’re too busy writing vulnerabilities as they cobble together applications and libraries they barely understand. How many wireless routers generate a config from user data plus a template. One’s lucky if they even do server side validation that ensures CRLFs not present in IP addresses and hostnames. And if Unicode is involved … a suitcase of four leaf clovers won’t save you. |
|