4 ms·
I'd be happy with regulations as basic as: - use HTTPS - no hardcoded security tokens in your requests - any personal data stored is inaccessible to the outs
by joncampbelldev 10y ago
I'd be happy with regulations as basic as:
- use HTTPS
- no hardcoded security tokens in your requests
- any personal data stored is inaccessible to the outside world without AT LEAST a password
- minimum password length for users
just anything to slow the shitstorm combination of incompetent developers and corner cutting executives.
AND such regulations are reasonably easy to enforce, anyone can check network traffic to verify protocol and api tokens or setup a new account with a short password, port scanning would catch most public databases.