in reply to Re^2: Taint mode... use all the time?
in thread Taint mode... use all the time?
That's not to say that a client program shouldn't be doing any kind of error checking. It should, to some extent. But the server shouldn't depend on that at all, and it should thoroughly check all input in minute detail (which is where taint mode helps out a bit, though it's not 100% foolproof).
Basically, it comes down to this: any code running on a machine which you don't control is code that you can't depend on in terms of security.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^4: Taint mode... use all the time?
by cbatjesmond (Novice) on Feb 13, 2005 at 19:42 UTC | |
by Anonymous Monk on Feb 14, 2005 at 15:09 UTC |