in reply to Re^3: Runtime Taint Enable
in thread Runtime Taint Enable
Hmm, interesting: I confess I don't use tainting in my CGI scripts despite the common recommendations, and this is part of the reason why - the data sources I want to choose not to trust are a small fraction of the whole, and the maintenance cost of detainting everything seems too high to me.I wonder whether there's a need for IO layers that can be used to create "tainted" data streams, and "untainted" data streams. (You still would have to consider $0 and the various environment variables though).
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^5: Runtime Taint Enable
by sgifford (Prior) on Feb 24, 2005 at 16:09 UTC |