4 ms·
I suppose a rouge developer can show their own login dialog box, but that is such a hack and should be pointed out by their boss, local paranoid (guess they are
by mathrawka 14y ago
I suppose a rouge developer can show their own login dialog box, but that is such a hack and should be pointed out by their boss, local paranoid (guess they are all gone?), or QA. They would have to capture the user's credentials and post it to the login handler themselves. Even the user might realize that it is not the login page and assume it is a phishing site.
The secret code for the encryption of the cookies is only installed on the login servers, and without that package installed, there would be no way to generate a valid signed cookie.
In short, there is no 100% guarantee a rouge developer could not do any damage, but it would be pretty hard to go unnoticed.
- jmathai 14y agoEx-Yahoo and former local paranoid. I agree with you. That's so unlikely that I'd be willing to put money that it wasn't a rogue developer.
- damncabbage 14y agoHow does an Acquired Company fit in with all of this? (An entire acquired company full of rogue developers? :-) )