I mean, of course I meant this was an SQL injection.
I mean, of course I meant this was an SQL injection.
> "don't accept ' or 1=1 -- as a password"
(the way that it's stated) implies that one should be checking input for possible SQL injection attacks and dropping the request, rather than sanitizing input so that the attack doesn't work, but the password is valid.
Only by using frameworks and DB drivers correctly (RTFM) is one able to accurately avoid SQLi. I would argue that "using software correctly" is by no means trivial and rarely happens in most systems that have less than NASA quality safeguards.
I would agree that most modern frameworks which are adopted by at least a few hundred developers tend to use best practices and a "security by default" mindset, but that's far from saying that "avoiding SQLi is trivial".