logoalt Hacker News

xorcistlast Saturday at 7:42 PM1 replyview on HN

It is, and other software handling untrusted data should also treat it as adversarial. For example, your package tool should probably not output raw package metadata to the terminal.


Replies

akerl_last Saturday at 7:45 PM

I think you’re missing the forest for the trees.