deny insecure parameters by default