| ▲ | traceroute66 15 hours ago | |
> They don't have time to ... Which is why they end up spending time on mea-culpa "we take your data security seriously, but clearly not seriously enough" emails when they inevitably get pwned by a completely predictable and avoidable SQL injection attack. The sort of startups you describe are jokes that barley take security seriously, let alone know what a pen-test or code audit is, let alone actually do them on a regular basis. | ||
| ▲ | euiq 15 hours ago | parent | next [-] | |
You can do safe parametrization with PREPARE, you don't need CREATE FUNCTION. Don't most PostgreSQL libraries handle such concerns for you, anyway? | ||
| ▲ | raverbashing 14 hours ago | parent | prev [-] | |
You don't need a stored procedure to use parameters with the query lol | ||