6 ms·
You're right. Sometimes. A hacker writing a quickie web server for the experience of doing so is laudable. This applies to lots of types of projects: toy OSes,
by generalk 16y ago
You're right. Sometimes.
A hacker writing a quickie web server for the experience of doing so is laudable. This applies to lots of types of projects: toy OSes, social networking protocols, web frameworks, what have you. Exploration is fun, and key to the hacker spirit.
The difficulty comes from knowing the limitations of your skills. I got my web programming chops by reading a bunch of PHP tutorials back in 1998 and throwing together some dummy pages that could read/write to a mysql database. Not long after I built a website for a good friend's business that was riddled with SQL injection and XSS holes. Luckily, we never got exploited, and years later on a rainy Sunday night I revisited the code and patched it up. Had we been hit, I don't know how badly that would have affected the company.
The same goes for home-grown crypto: sure, you might be able to apply a function you wrote and get something that looks like cyphertext, and maybe it's a fun project to learn about crypto. But when you don't know any better, you think you've done it right and you might unintentionally swindle some folks into paying for completely insecure crypto.
- count 16y agoHere, here! Learning someething, and selling (for money, or otherwise) the not-acceptable-for-use side effect of your learning something as a 'finished' product can be dangerous to the end customer. Not being able to skateboard well means you're going to fall and bust your knees or elbows or face. It's dangerous to you, and potentially comedic to your compatriots. Publishing a website full of XSS/SQLI problems and storing passwords and credit card numbers in plain text is dangerous to every person using your site, the business it's backing, and countless others in a 'could cost them real money and personal harm' fashion. It's also hilarious to some people (see HBGary / Valve / etc. hacks). Compare software engineering to physical engineering - you don't let the kid out of highschool who's good with Lego Kinnects build a bridge or skyscraper. He goes through years of formal training, and then years more of on the job training, working his way up from Bus Stop Shelters to Sheds to Houses, etc. before he gets to that point. THAT is the reason I'm highly critical of the efforts of people I know (or don't know in some instances). This shit ACTUALLY MATTERS beyond 'hey isn't that neat?'. If you're doing some project on your laptop to learn a technology - Awesome, can I help you with questions/guidance? If you've published something or sold something as a product and it's full of issues that could be serious problems to people down the line, What the fuck is your problem? Unlike real engineers, who have a formal body of governance and redress for customers of shitty engineers, software engineering is the wild wild west. Many people just blame the computer, without realizing there was a person unqualified for the job sitting behind the computer making it work improperly. Until that changes (if ever), then I think it's the DUTY of geeks and nerds to challenge each other as harshly as possible, in an effort to prevent certain disaster.
- swix 16y agoYou probably have one of the most poisonous perspectives one can have in this type of thing, this is exactly why the world sucks. There _NEVER_ is a reason to give "harsh" feedback, go read some kevin pollak or study psychology, humans are not "dogs" giving harsh or stupid feedback wont change the broken product. Offer your help, "Holy shit dude you have a XSS/SQLI in there, lets fix that up before you get in trouble". You are probably one of those people that wouldn't help someone on the edge of a roof trying to commit suicide. Just sayin.
- jokermatt999 16y agoThat last line is completely unnecessary, and rather ironic considering you were chastising someone for harsh feedback.
- swix 16y agoIt was by design, what do you expect if you are "One of those people", that you can be harsh to everyone and everyone is supposed to be polite and delightful towards you?
- count 16y agoI spend many, many hours helping people learn, and not by pushing them off the edges of buildings. Even google has had XSS style problems - that shit is HARD. One form field having filtering issues is one thing, a whole site of problems with absolutely no effort put in to mitigate what are, effectively, known issues, is an entirely different thing. If you're not worried about anything security related on a public website in 2011, you don't deserve to live on the public internet, and should jump.
- danenania 16y agoNot to diminish the importance of doing good work, but the reality is that knowledge and expertise are part of a continuum and even well-respected experts can easily make mistakes. If you're trying to make a living, you have to attempt to sell yourself at whatever level you're at, then work to keep improving. It's the customer's responsibility to do due diligence and discover potentially critical gaps in expertise, not the provider's to trumpet his/her own weaknesses. This is just the nature of a marketplace. The hacker who postures a bit in order to get a job he isn't truly suited for, but works hard to get up to speed and does his best, will be much better off in the long run than a hacker who declines the project, even if it leads to problems for the buyer later on. There's only so much you can learn without jumping in the deep end, but in order to get that chance, you often need to give the impression you've been swimming in the deep end for years. That's how the world works.