Earlier quoted context omitted.
I agree with you, but to me it is a problem that goes back to the people who made the decision of allowing admin accounts without a password. In a world where software stacks have multiple applications, programming languages and databases, it happens that people are not experts in everything. They make mistakes. Then there is a huge pool of companies who have poorly skilled devs coming from the Wordpress/Drupal/Prest…
> it is a problem that goes back to the people who made the decision of allowing admin accounts without a password. No. Just.. no.... Security of YOUR system is YOUR responsibility. > In a world where software stacks have multiple applications, programming languages and databases, it happens that people are not experts in everything. Hire one. > Maybe after this attack some companies ban it from their software stacks…
I agree. But what you are saying has nothing to do with whether a database should have sane defaults or not.
>> In a world where software stacks have multiple applications, programming languages and databases, it happens that people are not experts in everything. > Hire one.
You seem not to know much about the real world out there. Companies are struggling A LOT to find ANY people at all.
>> Maybe after this attack some companies ban it from their software stacks. > Or maybe decision makers realise that yes, you do need to pay for skills.
More money is not going to magically increase the pool of skilled software engineers around the world. If all the companies in the world increased what they pay, nothing would change, besides the fact that they would spend more money.