Definition
Plain language
A way of talking to a database that keeps the command and the user-supplied data in separate envelopes so the data can never become a command.
As stated in the literature
A parameterized database query in which SQL structure is transmitted and compiled independently of the bound values, eliminating SQL injection by carrying structure out-of-band rather than by sanitizing text.
Also called: prepared statements
Why it matters: It is the proven fix for an entire class of injection attacks, and it works by separating instructions from data rather than by trying to spot dangerous text.
For example, a login form sends the query shape "find the user whose name equals ?" and the typed name separately, so a visitor who types a fragment of database code just gets treated as a very odd username.
Heard on the show
“But a language model’s context window doesn’t have an equivalent of a prepared statement.”Episode 250 — The Same Model Refused a Backdoor, Then Its Own Sub-Agent Ran It