10 ms·
Not necessarily. You can design your system's security and then implement your features first. A good example would be "we know we need TLS, let's get a non TLS
by staticassertion 4y ago
Not necessarily. You can design your system's security and then implement your features first. A good example would be "we know we need TLS, let's get a non TLS version up first and then add it before release".
Pretty typical imo
- muhehe 4y agoI'd say it pretty typical prequel to "we intended to implement TLS, but then we forgot/were busy/attacked by medusas/.../had different prioritises"
- staticassertion 4y agoSure, but I don't think there's anything inherently wrong with incremental security.
- muhehe 4y agoI guess we won't agree on this. In my experience this is the sort of "good programmers don't do mistake X". Though technically possible, unreliable in reality.
- hnlmorg 4y agoThe problem is they have released it. Even if it’s considered a “pre-release” in versioning terms, it’s still been released to the public in actual terms. And given the nature of this software, it’s not unreasonable for people to expect a base level of security.