Earlier quoted context omitted.
And most college courses also don’t teach that.
Most college courses don't but most curriculums have some sort of security class. When we were learning assembly we used gdb to exploit faults in a C program (and we didn't get the source code so we had to read the assembly). There was also one for finding exploits exposed for a website that has a DB in the backend. Nothing prevents bootcamps from having those classes though.
> can be fine in a feature factory workplace. But having an engineer on your team who has no idea about infosec is an active danger. “I make a sql query from this string builder” / “we save the passwords in this database table” / “the AWS credential is here in the javascript code in the repository” / etc.