4 ms·
This is the operating procedure at every conceivable level. You would not believe how difficult it is to convince young developers raised on Javascript that cli
by weard_beard 2y ago
This is the operating procedure at every conceivable level. You would not believe how difficult it is to convince young developers raised on Javascript that client side validation is not enough, much less the business owners setting out functional requirements and budgets.
- dboreham 2y ago[flagged]
- weard_beard 2y agoThey'd be fired if they spent a penny more fixing it.
- UltraSane 2y agoMusk should be fired. He has irreversibly destroyed the Tesla brand.
- cluckindan 2y ago”You would not believe how difficult it is to convince young developers raised on Javascript that client side validation is not enough” At first read, I think you’re JSplaining, but I’m willing to give you the benefit of the doubt. How difficult is it exactly? Can you provide examples, perhaps even of the particular difficulties? Are the difficulties on the side of the convincer or the convincee, or both?
- nextts 2y agoI think it is something they have to experience. Tell them if they are happy with it, give me a $10 bug bounty. Then go hack a deploy of their branch. Then tell em to keep the $10 but remember the lesson.
- fn-mote 2y agoWow. I would never guess it was so hard to convince someone of this. “The code I write doesn’t have XSS or SQL injection vulnerabilities,” sure. At least those are plausible things to believe. Client side validation?? How could anybody believe in that?
- nine_k 2y agoI convinced fellow engineers who were adamant that the code they had written was OK by writing actual exploits against their code. Twice. Worked both times, without betting on money.
- wglb 2y agoAn axiom of secure programming is to never trust the client. You don't really know what the client is. Often it takes several penetrations via compromised/replaced clients to get the message through. Just look at all the discussions about why browser-based javascript encryption is problematic.