Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is, and other software handling untrusted data should also treat it as adversarial. For example, your package tool should probably not output raw package metadata to the terminal.


I think you’re missing the forest for the trees.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: