3 ms·
The phpfog guys really deserve praise for being so open on this issue. As a fellow engineer, being able to learn from their mistakes and see exactly what they c
by tjarratt 16y ago
The phpfog guys really deserve praise for being so open on this issue. As a fellow engineer, being able to learn from their mistakes and see exactly what they could have done ahead of time to avoid the disaster is priceless.
Just goes to show that those with the time to spend are the most likely to break your stuff, even if you pay "professional white hat hackers" to test your system.
- mtogo 16y agoOn the contrary, they knew of security vulnerabilities and intentionally left them unpatched, then blamed it on chance and timing when they got owned because of it. Avoid phpfog if at all possible, in my opinion.
- tjarratt 16y agoIf I lost $1 for each time I left a known vulnerability unpatched because I was convinced I had more important work to do, I would be a very poor man indeed. Honestly, there are very very few developers that fix security problems in beta environments before anything else. In my experience, it's more likely that you're fighting fires, handling outages, and dealing with problems of scale than fixing security vulnerabilities. Besides, isn't a beta the correct time to find these security issues? (Design / Alpha would be the ideal time, granted, but sometimes that's not possible.)