logoalt Hacker News

burnt-resistor08/01/20251 replyview on HN

Ruby does. Normalization of untrusted input isn't taught or discussed enough. Or each platform's regex security.

Honestly, I think all CS/EE programs should require an OWASP course and that coding should require regular continuing education that includes defensive coding practices for correctness, defined behavior, and security.


Replies

stouset08/01/2025

This was removed in Ruby 2.7. It was neat, but a bit of a blunt instrument.