3 ms·
...passwords that might be reused for the email addresses, and paypal, and... A web app might not touch real money, but a leak can still have real money conseq
by philh 9y ago
...passwords that might be reused for the email addresses, and paypal, and...
A web app might not touch real money, but a leak can still have real money consequences for the users.
- flunhat 9y agoSure, but in theory I can change passwords and maintain separate credentials for my banking-related needs. Short of auditing the Solidity contract code myself, there's nothing I can do to protect myself from the hacks themselves because the very mechanism by which money is transferred is riddled with bugs. This is mostly just semantics anyway - I'm just trying to establish that writing money-transfer software in a poorly designed language is, one way or another, worse than writing a web app in one.
- TeMPOraL 9y agoThere are also other consequences: - vulnerabilities can be used to attack users directly or through social engineering - (rare today, but definitely a problem with C++ web apps) you can break through a hole in the app and pwn the whole server