note reminds me a lot of when there was
2025-01-21 20:05:02.559286+01 by Dan Lyke 0 comments
This note reminds me a lot of when there was push back on "lint" or compiler warnings. that sense of "yeah, there's a code smell, but I can't see the bug so I'll ignore it" is real, and not good for our practice.
Too Many People Don’t Value the Time of Security Researchers
(Thinking in particular about how someone trolling Github found a $dbi->param(...) without a scalar coercion in the Flutterby content management code, and it didn't look exploitable, but I fixed that so fast...)