[Python-Dev] Re: Preventing Unicode-related gotchas (Was: pre-PEP: Unicode Security Considerations for Python)

2021年11月15日 00:39:03 -0800

Well,
Yet another issue is adding vulnerabilities in plain sight.
Human code reviewers will see this:
if user.admin == "something":
Static analysers will see
if user.admin == "something<hidden chars>":
but will not flag it as it's up to the user to verify the logic of things
and as such soft authors can plant backdoors in plain sight
Kind Regards,
Abdur-Rahmaan Janhangeer
about <https://compileralchemy.github.io/> | blog
<https://www.pythonkitchen.com>
github <https://github.com/Abdur-RahmaanJ>
Mauritius
_______________________________________________
Python-Dev mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/python-dev.python.org/
Message archived at 
https://mail.python.org/archives/list/[email protected]/message/IS2AWOSUNMHUXN6M4WPWT5QUTQFNNBZI/
Code of Conduct: http://python.org/psf/codeofconduct/

Reply via email to