Probably sells them on an image and liability benefit, too: "bank shouldn't be liable because we even went so far as putting former director of NSA in charge of our security. What more could we have done!?" Trying to counter liability in courts or with lobbying is main security model for big business. So, something like this is undoubtedly a benefit.
Or "don't accept ' or 1=1 -- as a password", for that matter. Internet-facing web system with several thousand users, just a year ago or so. Made me feel like I'm back in the '90s.
I mean, of course I meant this was an SQL injection.
Only by using frameworks and DB drivers correctly (RTFM) is one able to accurately avoid SQLi. I would argue that "using software correctly" is by no means trivial and rarely happens in most systems that have less than NASA quality safeguards.
I would agree that most modern frameworks which are adopted by at least a few hundred developers tend to use best practices and a "security by default" mindset, but that's far from saying that "avoiding SQLi is trivial".
> "don't accept ' or 1=1 -- as a password"
(the way that it's stated) implies that one should be checking input for possible SQL injection attacks and dropping the request, rather than sanitizing input so that the attack doesn't work, but the password is valid.