upvote
I think it's "don't use parsers written in unsafe languages".
reply
I think it's simpler: don't touch untrusted content unless/until you need to.
reply