Live data from Hacker News

Trusting clients is probably a security flaw

liberda.nl

11–20 of 150 posts

Re: Trusting clients is probably a security flaw

#11
post #9

In reality, since COVID, the coupons in Polish McD are so bad the app is almost useless. And the current version loads so sluggishly.

I haven't notice that, can you elaborate?

There used to be an abundance of coupons e.g. for 2 or 3 small burgers at an actually nice price.

Currently all coupons at or below 10 PLN are coffee, and not even cappuccino or flat white - but the "kawa czarna" or "kawa z mlekiem" which is watered down.

Re: Trusting clients is probably a security flaw

#12

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

Why would you want to continue working at such a place as a developer? It's not like it's hard to find another job as developer...

Re: Trusting clients is probably a security flaw

#13
post #4
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

Is there anything you know about McDonalds as an entity that would lead you to believe they know about, or would prioritize, building a secure app? Honestly, it’s amazing it’s not worse!

They have money and want to make more money? This seems like a straightforward question to answer.

Re: Trusting clients is probably a security flaw

#14
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

More importantly, why would anyone care? Is this some 5th dimensional chess marketing strategy by McDonald's? I hear more about their app these days than ever, and more than about any other security issue anywhere else.

Re: Trusting clients is probably a security flaw

#15

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

> People need to be able to say "I studied what you asked me to make, and refuse to work on this illegal, insecure, depressing cruft, and if you fire me for having professional ethics my lawyers will empty your company bank account."

This only works if everyone or the vast majority join unions. Otherwise, those who join will get penalised with lower offers or no offers at all.

Re: Trusting clients is probably a security flaw

#17

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

Why would you want to continue working at such a place as a developer? It's not like it's hard to find another job as developer...

> It's not like it's hard to find another job as developer...

In 2025? Haven't you noticed the massive layoffs by the big companies. Check r/cscareerquestions and read the posts from seniors unable to find a job

Re: Trusting clients is probably a security flaw

#18
post #4

Earlier quoted context omitted.

Is there anything you know about McDonalds as an entity that would lead you to believe they know about, or would prioritize, building a secure app? Honestly, it’s amazing it’s not worse!

They have money and want to make more money? This seems like a straightforward question to answer.

Yes, except the answer is opposite to what you think. Shitty and insecure apps make more money than decent and secure ones.

Re: Trusting clients is probably a security flaw

#19

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

Why would you want to continue working at such a place as a developer? It's not like it's hard to find another job as developer...

Entry-level jobs? Sure. Senior level and above? You must have been living under the rock for the past year.

Then again, mobile apps are like this tend to be junior work, outsourced to software mills that just burn through juniors cranking out garbage assembled 10% of polyfills and 90% of advertising SDKs. Yes, at this point of your career, you can still say "no" - the company will happily replace you with some other junior, while you replace some other junior somewhere else.

Re: Trusting clients is probably a security flaw

#20

In reality, since COVID, the coupons in Polish McD are so bad the app is almost useless. And the current version loads so sluggishly.

The app was always useless; I imagine you still can get showered with paper coupons if you ask about them, giving you the same deals without the burden of installing more crapware on your phone.
Post reply on HN