Hacker News new | past | comments | ask | show | jobs | submit login

> Nobody is talking about one-size-fits-all.

> I would love to be able to say ini_set('sanitize_rest', true) and deal with errors that might result from that knowing at least the strings are safe.

How is a magic ini setting to "make Strings safe" not a one-size-fits-all?

> People are talking about mitigating some stupid default behavior in a language.

What stupid default behaviour? Giving you data as its received and tools to validate/sanitize it as required?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: