You are viewing a single thread.
View all comments
58 points

Suddenly, very relatable today…

permalink
report
reply
19 points

I was just thinking how the developer of kbin made a post regarding a similar bug in kbin and some people made fun of him for missing something so obvious, and here we are 🤨

permalink
report
parent
reply
44 points

There’s only two kinds of people:

  1. Those who know no system is fool proof.
  2. Dumbasses.
permalink
report
parent
reply
9 points

I think everyone is on a journey from 2 -> 1, some just get there sooner than others :)

permalink
report
parent
reply
3 points

I’d call the second group fools because those are generally the ones that the system is trying to be safe against.

permalink
report
parent
reply
1 point

Foolproofness is an asymptote. It’s not achievable but we can always get closer.

permalink
report
parent
reply
0 points

If you are creating some software in 2023, it should not be vulnerable to SQL injection.

There’s no “but” or “unless”.

I really wished the presentation layer and session management had that kind of clear interfaces, instead we are stuck into only solving some 99.9% of CSS and 90% of CSRF. But SQL injection is 100% complete solved for good.

permalink
report
parent
reply
11 points

The best developers can admit they missed something, fix it, and move on to the next thing.

permalink
report
parent
reply
8 points

The difference is that here lots of people posted about it and action was taken. If this was corporate owned, any suggestions of a problem would have been removed or denied, and months later after it hits public media they would have admitted there might have been a problem, and here’s some free identity theft protection if you feel like you were affected.

permalink
report
parent
reply
3 points

True. Looking at lemmy GitHub, it looks like everyone is swamped.

permalink
report
parent
reply
5 points

How come?

permalink
report
parent
reply
8 points

Because there was a xss bug in Lemmy cause by not escaping some inputs

permalink
report
parent
reply
7 points
*

Because he doesn’t know the difference between an SQL injection and a Cross site scripting attack.

Link for those who would like to learn more.

permalink
report
parent
reply
22 points

Or because both relate to not sanitizing your input

permalink
report
parent
reply

General Discussion

!general@lemmy.world

Create post

Welcome to Lemmy.World General!

This is a community for general discussion where you can get your bearings in the fediverse. Discuss topics & ask questions that don’t seem to fit in any other community, or don’t have an active community yet.


🪆 About Lemmy World

🧭 Finding Communities

Feel free to ask here or over in: !lemmy411@lemmy.ca!

Also keep an eye on:

For more involved tools to find communities to join: check out Lemmyverse!


💬 Additional Discussion Focused Communities:

Rules

Remember, Lemmy World rules also apply here.
  1. See: Rules for Users.
  2. No bigotry: including racism, sexism, homophobia, transphobia, or xenophobia.
  3. Be respectful. Everyone should feel welcome here.
  4. Be thoughtful and helpful: even with ‘silly’ questions. The world won’t be made better by dismissive comments to others on Lemmy.
  5. Link posts should include some context/opinion in the body text when the title is unaltered, or be titled to encourage discussion.
  6. Posts concerning other instances’ activity/decisions are better suited to !fediverse@lemmy.world or !lemmydrama@lemmy.world communities.
  7. No Ads/Spamming.
  8. No NSFW content.

Community stats

  • 653

    Monthly active users

  • 483

    Posts

  • 9K

    Comments