4 ms·
You would hope that. I’ve been in infosec doing application security as a consultant a long time. Developers have often destroyed my hopes :)
by bitexploder 6y ago
You would hope that. I’ve been in infosec doing application security as a consultant a long time. Developers have often destroyed my hopes :)
- vageli 6y ago> You would hope that. I’ve been in infosec doing application security as a consultant a long time. Developers have often destroyed my hopes :) I used to work at a big bank in the US and the parent's description sounds exactly like how it would work.
- earthboundkid 6y agoGovernment and banks have been continuously using computers since the 60s, so as a result there’s a lot of “fancy web API to collect data… that gets batch processed by an ETL on a mainframe overnight.” Much more of it than I realized as a young dev at least.
- bitexploder 6y agoYou could be right but I have found almost this exact bug in production systems (credit card oracle sitting on the public Internet of a big card processor with no rate limiting and a really obvious timing delta). Both scenarios (batch or live processing) are pretty likely IMO. Just depends on what mess of APIs you happen to end up on.