Comment by insanitybit
16 hours ago
That doesn't seem to prove their point at all and it clearly demonstrates the tractability of escaping inputs for domains like sql/html.
16 hours ago
That doesn't seem to prove their point at all and it clearly demonstrates the tractability of escaping inputs for domains like sql/html.
The point is lost somewhere. Prepared statements for SQL, innerText for HTML and similar do not show tractability of escaping, they sidestep the escaping problem altogether.
Those are interfaces where escaping is no longer needed precisely because they deinterlace instructions from data. Escaping problem inherent to instruction+data channels. Yes, deinterlacing is not solution, not futile attempts to escape.
innerText escapes the text, that's the whole point of Trusted Types. Escaping isn't just "needed", it's literally how those features work.