4 ms·
Interesting question. I would say - Password only ssh logins; Old / Vuln libs; non tests covered code; XSS and SQL Injection from all the code. - But this is r
by lfx 10y ago
Interesting question.
I would say - Password only ssh logins; Old / Vuln libs; non tests covered code; XSS and SQL Injection from all the code. - But this is really boring.
AI witch threatens to take over developers occupation - this is more interesting idea for future consideration.
But really I just want to see one thing to be destroyed - idea that creating new tools will solve all the issues (looking at you JS world) instead of improving existing ones or even real deep thinking about the problem beforehand. And then dropping it (new tool) after something new more shiner comes up.
- odonnellryan 10y ago> Password only ssh logins Dear lord, this still happens? :)
- dozzie 10y agoOf course not. Your SSH key on a server lands there magically using quantum entanglement-based key distribution protocol.
- odonnellryan 10y agoThis is a little funny, because I haven't spun up a new server in years with a password. They've all had my public keys from the get-go.
- dozzie 10y agoHow often do you deploy servers? And how much of that is cloning[#] a prepared virtual machine? I realize that there are ways to install an OS and preconfigure it at one go, but those need some non-trivial mechanics in place. Also, it is (was until quite recently) much easier to share a password between machines with LDAP than having the same with user keys. Programmers tend to have quite skewed idea on what operates the production, as they rarely see the details. [#] Cloning an already installed system is usually a stupid thing, unless you make sure that SSH host keys don't get shared (and several similar things).
- odonnellryan 10y ago> And how much of that is cloning[#] a prepared virtual machine? Shouldn't this or using deployment scripts be "almost always?" > much easier to share a password between machines with LDAP than having the same with user keys. I think this is a different subject, no? I've never had to do this. > Programmers tend to have quite skewed idea on what operates the production, as they rarely see the details. I've worked as both a programmer and a sysadmin for large enterprises, so I've seen both sides! > Cloning an already installed system is usually a stupid thing, unless you make sure that SSH host keys don't get shared (and several similar things). No it isn't. It's fine to have a "base" image that you use to then run deployment scripts on, if done correctly. Way better than having to go through a 20+ step process of securing a new Linux or Windows box :)
- krapp 10y ago>Dear lord, this still happens? :) For what it's worth, every time I've seen this question asked here, the answer has been yes.
- odonnellryan 10y agoHaha, I know...
- auganov 10y agoAnd unprotected keys while we're at it.