Complaining about bad data in that situation is like complaining that an admin could hit the power switch.
Or maybe I've completely misunderstood the purpose of this software.
Complaining about bad data in that situation is like complaining that an admin could hit the power switch.
Or maybe I've completely misunderstood the purpose of this software.
1) The user isn't always the one providing user input.
2) When the user does provide input, the user isn't always smart.
3) Users do things that you never would have conceived.
Unsanitized system() calls are even worse than leaving your system wide open to a sql inection attack.
The same user who feeds in the values for 'system' is also trusting the program with their bitcoins! This is (in my opinion) like saying "bash" is a security issue because you can give it bash scripts.
> why shouldn't my financial system be as open as bash?
Oh my lord...
I put my cups in the dishwasher, not the autoclave. I use 2fa for my financial accounts, but not for my frisbee league. Security is about appropriate paranoia.