Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, the SQL example was lame. There are too many PHP "tutorials" which attempt to demonstrate one concept while blatantly ignoring basic security principles. In this case, the example should have used prepared statements with either MySQLi or PDO.


I read "PHP: The Good Parts" on the train last night, and face-palmed the whole way - it's ALL written in an insecure style, except for the one chapter that's explicitly dedicated to security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: