logoalt Hacker News

n_eyesterday at 4:06 PM1 replyview on HN

The "data" is part of the tax simulation source code, not untrusted input, so such an attack vector doesn't exist.


Replies

catlifeonmarsyesterday at 4:09 PM

Yet. You’re adding one other thing that authors need to keep in mind when developing the product, fixing bugs, and adding features. The fact that the input must be trusted is not an intrinsic part of the business logic, it’s an additional caveat that humans need to remember.

show 1 reply