logoalt Hacker News

pryelluwlast Saturday at 4:29 PM1 replyview on HN

Im still fixing sql and db command injection through APIs from juniors and now vibe coders. This just adds more work to do.

The ITT/TTI and TTS/STT have been particularly annoying to protect against. I don’t feel we’ve matured enough to have solid protections against such vectors yet.


Replies

wglblast Saturday at 4:59 PM

Write a prompt that asks to detect sql injection in each source code model. Or other security issues.

show 4 replies