Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
@RodrigoF No, but I can't imagine it was the most life affirming experience to have me standing over his shoulder while he changed his password, while I mansplained 2 factor auth.
-
Today i showed my boss i can easily retrieve his password in chrome through inspect element. And he is freaking out.
He keeps showing me different services to secure this (lastpass, keepPass etc..) and I keep finding flows in those services. It's been fun week. -
Until there are lawsuits and class actions, software won't magically become secure.
Related Rants
We recently took over development of an app. Upon inspection the API had no security, and passwords were stored in plain text. While the manager was slightly concerned, it wasn't a big deal....
That was until, using only a browser, I found the bosses account and personal email address.
Minutes later I was in his gmail, Facebook and credit cards account.
Improving security is now concern #1, and my boss is "suffering" 2 factor authy on everything.
undefined
api
boss
security 101