3 ms·
Also ignores any required authentication. This is basically just a load test. Why has the security field degenerated to such a shitshow?
by fisf 3y ago
Also ignores any required authentication. This is basically just a load test.
Why has the security field degenerated to such a shitshow?
- pixl97 3y agoDegenerated? Welcome to the shitshow, it's always been this way in computing, security is always an afterthought.
- zer00eyz 3y ago>>> security is always an afterthought. Not everywhere. Some places take security seriously. Banks do not fuck around on this front. Some places security is where they shove all the diversity hires. It's not an afterthought it's a dark corner no one cares about. Other places have security as theater. I know of quite a few companies who have security tools implemented just to have someone to blame when the fuck up happens. XXX was our provider, were sorry sue them, were going to! The reality is that the decision makers heard what they should do, and made a choice, not understanding the risk. In that regard some of them are getting better (see theater), and making it worse.
- pixl97 3y ago>Banks do not fuck around on this front. So, I have a fair bit of insight into bank operations and their programming practices. The vast majority of it is security theater. There is quite a bit of decent code near the core moving money portions, but once you start getting into the webapp side of things it quickly devolves into "Please do the basic minimum to ensure security of this application".
- HankB99 3y agoSMS 2FA