How to Write Injection-Proof SQL
schneier.com
schneier.com
Count.
Buffer overflow cost so far to the industry? In the billions, at least: companies buy hundreds of millions of dollars of products every year as countermeasures against them. And that's for a bug whose fix can be described in one word.
But the advice is also simple: 99% of the problems are solved by using parameterized queries ( pretty much every language/db library has them )
I've always wondered why this isn't just a no-brainer.
Most people just don't have a security mindset. They are happy when it works the way it is supposed to.
Preventing buffer overflows is simple and well understood, yet it's still a problem. Preventing SQL injection is not as simple.* He's pointing out that if we have big problems even in the presence of simple solutions, we'll have even worse problems with not as simple solutions.
*Your solution might be "simple," but it's still more complicated that making sure you don't overrun your buffer.
I misread that