Hacker News new | ask | show | jobs
by matthewmacleod 4050 days ago
I don't necessarily disagree with you, but it's still an astonishingly bad practice as a default.

If there's one thing we should have learned from Rails' various security failures, it's that things must be secure by default.