Think of all the money spent combatting SQL injection attacks. Now we apparently have people deploying systems that fundamentally can't distinguish between code and data, and using pants-on-head 1990s tactics to fight "bad" input on a case-by-case basis. The amount of technical debt this will create is mind-boggling.
No comments yet