• How can someone update a row they cannot see?

    How do you abuse select?

    Yes you can grant insert and update without select. I am of the opinion that you control access using stored procedures and views.