8 ms·
You shouldn't be touching the server-side code if you find this hard to keep straight.
by dfedbeef 2y ago
You shouldn't be touching the server-side code if you find this hard to keep straight.
- Cu3PO42 2y agoUltimately, I don't disagree. However, I also try to make it a habit to not blame people for not knowing something. This presents as a structural problem in that company: they needed to hire people who do know how to secure server code and put them into a position to do so. Blame the company and those who decided to save every last penny in personnel cost.
- valenterry 2y agoYeah, the people who put those people into the position to touch server side code are to blame. But then the OP is right: the people having made these code changes should really not have touched anything server side or even anything security relevant in the beginning.
- hackernewds 2y agoright*
- benoau 2y agoI agree they should just quit but that requires experience to understand too. By the time they've learned that, they have also learned that client-side access controls are decorative.
- consteval 2y agoThey shouldn't have to - the architecture should be made in such a way that permission checks are done without you specifically having to call them every time. This is the entire reason middleware exists!
- valenterry 2y agoWell, but apparently they let people create the architecture who just shouldn't have touched the backend code. That's the whole point. Since it was not just a single endpoint or so - it was everywhere!
- namaria 2y agoPeople getting paid to create software should know better then these basic mistakes.
- _pete_ 2y agothan
- overstay8930 2y ago> I also try to make it a habit to not blame people for not knowing something There’s a point where critical thinking skills come into play, I’ve seen people walked off the premises for doing stuff like this with customer data. Actual seniors who have never been blamed for anything are suddenly intolerable threats to the company because they didn’t bother to check what they were doing and forced the company to disclose a breach.
- robbie-c 2y agoSexual preferences and such are special category data, and if you are an engineer dealing with this stuff you should treat it as though data breaches could get someone killed. Sure, part of the responsibility of this is on management, but it's absolutely on the engineers too.
- dfedbeef 2y agou are wise and right
- tgv 2y agoSo if someone who can't drive, finds a car with the keys in it, and starts driving it, and causes an accident, who do you blame? And do you have any reason at all to believe the backend people didn't know? They wrote a fair amount of code and infrastructure, so they cannot have been blank slates.
- yawaramin 2y ago> who do you blame? The people who hired the person who can't drive and gave them a job as a driver. > do you have any reason at all to believe the backend people didn't know? Well, either they knew and wanted to implement proper auth and were prevented from doing it, or they knew and couldn't be bothered, or they didn't know that their backend system wasn't properly locked down and were too incompetent to have a clue.
- devnullbrain 2y agoYet after decades of this messaging, we still have these people touching the server-side code. Is it likely another few years of the same messaging will fix it?
- jfoutz 2y agoEternal September. Everyone starts somewhere, it’s just all the time now. In ten years, the dev will explain to a junior how bad they messed up, and why they have to validate this way. Well, I don’t know, but that’s what I hope.
- ifdefdebug 2y agoyeah now imagine another engineer go "my first bridge just fell apart the first time a real truck tried to cross over it lol" or "man my first plane crashed so hard"...
- jfoutz 2y agoYa know, the Roman tradition was, you gotta stand under the bridge while the army marches over it. If it collapses, you die too. Maybe there's something to having nudes of that dev. Real engineering is expensive. And hard. moving atoms around is tough. I've never cut stone, but I've melted and cast copper and aluminum. That's real and dangerous work. Computation is cheap and plentiful. And I kinda like having full control of "stuff". But maybe we do need licensing or personal liability. If I could wave a magic wand, and make that exist, I don't really know what rules I'd put in place. How do you think people should get skilled up?
- bugtodiffer 2y ago> How do you think people should get skilled up? You didn't ask me but I can give you my answer: not on prod and with a lot of reviews!
- floating-io 2y ago> Maybe there's something to having nudes of that dev. Most users of these sorts of app don't pay enough attention to security to care. Do you really think that most developers are any better? Most developers are just normal people who happen to be able to write a bit of code and convinced someone to employ them. Just like anyone else, far too many live under the delusion that "it can't happen to me." Translation: making them eat their own dogfood and risk their own embarrassment won't help; they would have to know better, first! =)
- benoau 2y agoJunior developer probably opened a Jira ticket, saw a UI of a permission dialog, and did exactly that task with nobody senior enough to know better. That's how you reproduce the bugs that were in-fashion 15 - 20 years ago in my experience!
- bugtodiffer 2y agoSeems like a solid development cycle. Junior tries something -> hit production I do not see multiple issues with this.
- Ntrails 2y agoHey, it worked on my machine
- intelVISA 2y ago9 out of 10 PMs love this one hack to boost velocity they were probably thinking what a 10x engineer they'd found to be so rapid at delivery...
- XenophileJKO 2y agoThis is so true. I've seen this so many times. The darling of product, who can deliver so fast. They leave a trail of smoking rubble and half working features behind them.
- blitzar 2y agoWhy can't you be more like darling of product over there. What do you even do around here; all you seem to ever do is take darling of products code and make a few changes (which I don't understand) and committing it as your own work. It appears you are either trying to take credit for darling of product or are sabotaging their amazing 10x work.
- dfedbeef 2y ago
- FragrantRiver 2y agoThey didn't ;)
- poincaredisk 2y agoI work in security and I don't trust myself to tie my shoes correctly every day. OPs comparison is great. Bounds checks are easy. There are many overconfident C++ programmers that say they would never introduce a vulnerability like that. But it still happens, because in this class if vulnerabilities it's often enough to forget one check.
- dfedbeef 2y agoI feel bad now I'm sorry to the person I replied to lol. I didn't mean 'you' I meant a generalized third party person.