Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So it could be that they create a mysql "database" for each user, and give them all the privileges needed there, and no privileges anywhere else.

And conceivably you could have some kind of proxy that looked like mysql but actually sanitized/logged/whatever any queries, before passing them on to the real server.



Since that would take more effort and time than simply doing it right, I call Occam's razor.


I wasn't trying to argue that it would be the correct approach, just a possible explanation.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: