Early in my career I trusted data once it was “inside” my system. It came from my own frontend, my own service, so surely it was fine. I sprinkled little checks wherever I happened to remember, and called it careful.
It wasn’t careful. It was scattered. The same field would get half-validated in three places and fully validated in none, and every function quietly assumed some other function had already handled it. The gaps between those assumptions are exactly where the bad data — and eventually the bad actor — walks in.
The habit that changed everything was simple: pick the boundary and defend it there. The moment data enters the system, I check it hard, in one place, completely. After that line, the inside gets to trust it, because I actually earned that trust at the door instead of pretending it was never a risk.
It made the code calmer, too. The core stopped being paranoid. It didn’t need to re-ask “is this real?” at every step, because the answer was settled at the edge.
I don’t trust input because of where it came from anymore. I trust it because it crossed a border I was watching.
– Serguey Asael Shinder
Leave a Reply