She was mostly looking for validation, since the guys in the group thought that hashing the passwords on an online banking application is waste of time, and the best way to handle login is to send the whole user database to the front-end so you can match the unhashed password to the correct account

Colleges should lower their limits for stabbing

  • Highalectical@lemmygrad.ml
    link
    fedilink
    English
    arrow-up
    18
    ·
    7 months ago

    Holy shit, not hashing your passwords is already dumb, but what brain genius had the idea to send the whole DB to the fronted?

    • riseuppikmin [he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      11
      ·
      7 months ago

      People act like this is stupid but imagine how great it’s gonna be when I find out every single one of my users uses this specific device and I’ve created the world’s best local cache.