in reply to Linux.com and CGI
It was a good article, but I did not like this line:
Thus, taint mode is only as good as your ability to write a regular expression that matches secure strings. For that reason we find taint to be overkill and not much useful for the majority of CGI programmers, though of course others would disagree.
For experienced CGI programmers - MAYBE - although I still believe it should be used the majority of the time. However, in this case the article is geared towards newbies, hence, IMHO, he should not dismiss Taint mode so easily.
The article did mention security, showed regexes to clear out anything other than wanted characters, provided a link to more discussions about security, and mentioned taint mode, then dismissed taint mode as useless.
*sigh*