in reply to To taint or not to taint?
I only use taint if my program has to potential to do something the caller isn't able to - and if the caller is potentially hostile. But I write a large numbers of programs that run under the same privileges the user already has.
I think one should always think whether you should use taint mode or not. And use it when appropriate. Neither "always use taint" nor "never use taint" appeals to me.
|
|---|