Earlier quoted context omitted.
Junior developer probably opened a Jira ticket, saw a UI of a permission dialog, and did exactly that task with nobody senior enough to know better. That's how you reproduce the bugs that were in-fashion 15 - 20 years ago in my experience!
Seems like a solid development cycle. Junior tries something -> hit production I do not see multiple issues with this.
Vulnerabilities in the Feeld dating app
61–70 of 150 posts
Re: Vulnerabilities in the Feeld dating app
#62Earlier quoted context omitted.
This is what happens when both founders are not technical. I use the app and it was obvious from day one it’s been designed and implemented by the lowest bidder.
Not necessarily the lowest bidder. It's quite easy for a consulting company that is bad at development to make a convincing pitch to a nontechnical founder as long as they're better at sales than they are at development.
Re: Vulnerabilities in the Feeld dating app
#63Earlier quoted context omitted.
It's been observed by many that making bad things seems to be a lot more profitable these days than making good things
It's not making bad, it's making cheaper/faster. They probably hired less experimented developers or didn't give them proper time to implement the features they wanted.
Re: Vulnerabilities in the Feeld dating app
#64Re: Vulnerabilities in the Feeld dating app
#65I'm not terribly surprised. I use it but would describe it as incompetently put together as my bank app? maybe worse, it barley functions at all. I dont know how they managed it.
Between it and Fetlife there's some huge issues with those communities just sticking with the first app that emerges regardless of quality
Re: Vulnerabilities in the Feeld dating app
#66Earlier quoted context omitted.
You shouldn't be touching the server-side code if you find this hard to keep straight.
Ultimately, I don't disagree. However, I also try to make it a habit to not blame people for not knowing something. This presents as a structural problem in that company: they needed to hire people who do know how to secure server code and put them into a position to do so. Blame the company and those who decided to save every last penny in personnel cost.
There’s a point where critical thinking skills come into play, I’ve seen people walked off the premises for doing stuff like this with customer data. Actual seniors who have never been blamed for anything are suddenly intolerable threats to the company because they didn’t bother to check what they were doing and forced the company to disclose a breach.
Re: Vulnerabilities in the Feeld dating app
#67Earlier quoted context omitted.
You shouldn't be touching the server-side code if you find this hard to keep straight.
Junior developer probably opened a Jira ticket, saw a UI of a permission dialog, and did exactly that task with nobody senior enough to know better. That's how you reproduce the bugs that were in-fashion 15 - 20 years ago in my experience!
Re: Vulnerabilities in the Feeld dating app
#68Re: Vulnerabilities in the Feeld dating app
#69Earlier quoted context omitted.
It's been observed by many that making bad things seems to be a lot more profitable these days than making good things
It's always been like that. The costs involved with maintaining garbage are infinitely more than maintaining something well built. This is why software is so lucrative.. because the true cost of the software isn't how much you pay for it .. it's "how much is it going to cost you to change to something else?"
unfortunately trash is cheaper and faster, and it takes a certain kind of genius insanity to sell something well built that doesn't exist yet.
Re: Vulnerabilities in the Feeld dating app
#70Earlier quoted context omitted.
yeah now imagine another engineer go "my first bridge just fell apart the first time a real truck tried to cross over it lol" or "man my first plane crashed so hard"...
That's an interesting idea. Bridge builders and flight sims are used in industry to test to see if a bridge design will fail or if a plane will crash. They're not limited to oversimplified and fun video games. I wonder if there's a market for a "write a CRUD app and let it loose on the Internet and watch it get pwned" simulator/game.