Hacker News new | ask | show | jobs
by saintfire 43 days ago
> If I ever start using any query strings, I’ll allow only known parameters.

They aren't saying the concept of query strings are bad, They're saying unsolicited query strings during referal are the issue.