ndw’s avatarndw’s Twitter Archive—№ 32,601

  1. Complete amateur hour, Aspiration. If the name of a contact includes "&", attempting to send a payment to them generates an API error. That's spectacularly bad and smells of an app not sanitizing its inputs, a well known attack vector for hacking.