in reply to Re^3: Runtime Taint Enable
in thread Runtime Taint Enable

Hmm, interesting: I confess I don't use tainting in my CGI scripts despite the common recommendations, and this is part of the reason why - the data sources I want to choose not to trust are a small fraction of the whole, and the maintenance cost of detainting everything seems too high to me.
I wonder whether there's a need for IO layers that can be used to create "tainted" data streams, and "untainted" data streams. (You still would have to consider $0 and the various environment variables though).

Replies are listed 'Best First'.
Re^5: Runtime Taint Enable
by sgifford (Prior) on Feb 24, 2005 at 16:09 UTC