Live data from Hacker News

Trusting clients is probably a security flaw

liberda.nl

1–10 of 150 posts

Re: Trusting clients is probably a security flaw

#4
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

Is there anything you know about McDonalds as an entity that would lead you to believe they know about, or would prioritize, building a secure app?

Honestly, it’s amazing it’s not worse!

Re: Trusting clients is probably a security flaw

#5
post #4
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

Is there anything you know about McDonalds as an entity that would lead you to believe they know about, or would prioritize, building a secure app? Honestly, it’s amazing it’s not worse!

The said root checks for example?

Re: Trusting clients is probably a security flaw

#6
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

This sort of things happens a lot. A few years ago a British bus company put certificates in the app to sign tickets.

The HSBC UK app will not run if you have any apps installed from outside play store. I cannot log into the website without the app. Luckily all I have with them is a lightly used credit card with a low limit so I have just stopped using it and rely on paper statement.

I find it disturbing that any app can examine your device in this much detail.

Re: Trusting clients is probably a security flaw

#8
Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time.

Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk. Some poor sap had to make this, probably sighing and shrugging at the end of each line of code.

Unions or professional body membership is becoming more important for programmers. People need to be able to say "I studied what you asked me to make, and refuse to work on this illegal, insecure, depressing cruft, and if you fire me for having professional ethics my lawyers will empty your company bank account." Otherwise technologists become just tools of destruction.

Re: Trusting clients is probably a security flaw

#10
post #4

Earlier quoted context omitted.

Is there anything you know about McDonalds as an entity that would lead you to believe they know about, or would prioritize, building a secure app? Honestly, it’s amazing it’s not worse!

The said root checks for example?

Which indicate that the management wants to feel good, not that the app developers care about actual security.
Post reply on HN