3 ms·
Facebook joins Patreon in the "why somebody should make sure our python web framework debug mode isn't enabled in prod" club.
by cc-d 8y ago
Facebook joins Patreon in the "why somebody should make sure our python web framework debug mode isn't enabled in prod" club.
- makomk 8y agoPatreon's screw-up was a lot more embarassing though - they apparently left an actual Python shell exposed to the web for at least a week after someone warned them about it, and their entire user database was exfiltrated and posted on the net as a result.
- meowface 8y agoYep. Every company will face security issues; it's unavoidable. But what happened to Patreon should make people seriously question trusting them with your personal information or money. (They probably use a 3rd party payment processor who has much better security practices, but still. Also, that 3rd party doesn't do you much good if an attacker with control of your production web/application servers or CDNs is intercepting credit card form data before it's sent off.) Facebook has had vulnerabilities and exposures, but nothing like that.