When I interview developers, I generally ask some basic questions about security - "Explain to me what an XSS attack is?", or "How would you defend a web app against SQL injection?" Basic stuff, which - to my mind - literally every person who develops anything which is on the web should know. And a surprising number of people - even "senior" developers can't answer this stuff. It's really worrying.
When I interview developers, I generally ask some basic questions about ____ - "Explain to me what _____ is?", or "How would you _____?"
Basic stuff, which - to my mind - literally every person who develops anything which is on _____ should know.
And a surprising number of people - even "senior" developers can't answer this stuff. It's really worrying.