• @[email protected]
    link
    fedilink
    English
    33
    edit-2
    8 months ago

    Prepared statements, mostly. You define the query using variables, turn that query into a language-dependent object, assign values to those variables, then execute the statement. The values will be passed verbatim, without any parsing.

    Or, since we’re talking about a password, you could encode or encrypt it before inserting it into the query string. The fact that the website could be negatively affected by phrases in the cleartext password is very concerning.

    • @[email protected]
      link
      fedilink
      88 months ago

      At best, it means they’re storing your password instead of just a salted hash. And that’s horrible.