Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I'd like to think that nowadays we'd use self-describing, upgradeable protocols.

That would open a whole new can of security worms though. Being able to modify a protocol in-band is something we're starting to move away from. Things are becoming more static as a precaution, like stored procedures on SQL so an attacker can't inject a change.



Stored procedure was the norm when I was a young programmer. Dynamic SQLs are recent and was the cause of SQL injection vulnerabilities.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: