security/sql-injection-how-a-stray-quote-mark-turns-data-into-instructions.md
SQL injection: how a stray quote mark turns data into instructions
A search box looks harmless, but if a program builds its database question by gluing text together, a stray quote mark can turn a visitor's words into instructions. That bug is called SQL injection.
Type your own input into a live playground and watch where the data ends and the instructions begin, then see the one-line fix, placeholders, working in real Python output.

$ ls security/
see all →
security/who-really-owns-this-link-read-a-web-address-before-you-click.md
Who really owns this link? Read a web address before you click
A scary message says your account is locked and the link has your bank's name in it. Does that make it safe? No: only the host part of a…
security/how-websites-check-your-password-without-ever-storing-it.md
How websites check your password without ever storing it
A well-built website never saves your password. It saves a hash: a fixed-size fingerprint that's quick to compute and impossible to run…
security/why-a-long-password-beats-a-complicated-one.md
Why a long password beats a complicated one
Websites tell you to add a capital, a number and a symbol. But length does far more for a password than funny characters ever can. Count…