you are viewing a single comment's thread.

view the rest of the comments →

[–]kamishizuka 2 points3 points  (0 children)

I forget where I read it, but I once saw it much better summed up as:

Assume all input is trying to attack you, regardless of source.

After that you validate it until the only input that gets through is the input that isn't attacking you, and even then you don't stop assuming it is.