• @rtxn
    link
    English
    31
    edit-2
    4 months ago

    Prepared statements, mostly. You define the query using variables, turn that query into a language-dependent object, assign values to those variables, then execute the statement. The values will be passed verbatim, without any parsing.

    Or, since we’re talking about a password, you could encode or encrypt it before inserting it into the query string. The fact that the website could be negatively affected by phrases in the cleartext password is very concerning.

    • @surewhynotlem
      link
      54 months ago

      At best, it means they’re storing your password instead of just a salted hash. And that’s horrible.