default-deny in webapps?
Saturday, March 4th, 2006This is … all about dbms’es — a topic I’m getting quite intimate with this semester (what with the whole “writing our own in class” thing and all).
I’m thinking … from a security perspective, default-allow is a bad thing, and default-deny is a good one — ie: you should have to explicitly enumerate the things [...]