''The number one thing for developers to realize is that you need to treat input as evil,'' he said.