He sounded credible, what am I missing?
obviously someone can
especially in a relational database - even a script kiddie could query the database with a simple sql query