4 ms·
I must be missing something. How is it possible that they don't have umpteen copies of the sources checked out of whatever source control system they are using?
by rll 16y ago
I must be missing something. How is it possible that they don't have umpteen copies of the sources checked out of whatever source control system they are using? Even if the central repository was destroyed, every developer should have a more or less recent version checked out somewhere.
- zacharypinter 16y agoLooks like a PHP site. I'm guessing they weren't using version control and were instead just editing the files over FTP.
- enko 16y agoIf that turns out to be the case .. I wouldn't go so far as to say they deserved it, but my sympathy would definitely be pretty limited.
- nwp 16y agoI agree. There is absolutely no excuse for not having some sort of source control and deployment system in place at an organization with a commercially deployed solution. Why would anyone regard such a system as optional? It is irresponsible.
- Androsynth 16y agoso php == ignorance? are we really going to make that assumption? thats just foolish.
- deleted 16y ago[deleted]
- zacharypinter 16y agoNot at all. Just trying to figure out how they might have a dev environment setup where there isn't a copy on local developer machines. Not all languages make that easy. PHP does.
- Androsynth 16y agook, i get your point now. They may have been using version control, but if they were checking out to a server and editing remotely, and that server happened to be the same server where the central repo was stored, it could explain how one attack would get it all.
- MichaelGG 16y agoNo, but PHP easily allows a "edit source on server" as a deployment model.
- random42 16y agoSeriously, You dont even need a security attack for losing the changes with this model. A nice little "harddisk" failure would do the trick for you. :)
- nupark2 16y agoNo, but given how often I've seen PHP developers do this, even at larger organizations, it's a plausible explanation.
- consultutah 16y agoWe deploy from a special deployment repository. This has a bunch of advantages: 1) You can revert to a known state. 2) You can see if anything has changed on individual servers using svn stat. 3) You have a history of what has changed on production. Any scm would work just fine.
- alinajaf 16y agoWe're a PHP shop and we have version control. All but one of the companies I worked at used _some_ sort of version control, so it just doesn't make any sense that deploying an old release should be so tough.