Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Usually because the password database is able to be compromised by some code injection bug (e.g. SQLi). In order to prevent this you should be using a library the makes it impossible to mix code and input data like that.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: