1392
Comments (235)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
2
dev01 2 points ago +2 / -0

That's not the software engineers job. That's a penetration testers job.

5
CantStumpTheTrump 5 points ago +6 / -1

Security is everyones job.

1
dev01 1 point ago +1 / -0

A nice thing to say that functions as an excuse to avoid spending money on process improvement, actual security audits and bullet proofing.

2
Artymisfoul 2 points ago +2 / -0

That is dumb. Speaking as a software engineer you do not allow sql injection when writing software.

0
dev01 0 points ago +1 / -1

Not deliberately. But it's not our job to do in depth security testing

1
deleted 1 point ago +1 / -0
1
dev01 1 point ago +1 / -0

It is excusable, because people are human and make mistakes.

Escaped security holes are a development PROCESS problem not a programmer problem.

1
CantStumpTheTrump 1 point ago +1 / -0

I'm going to be straight up; you're one of those guys everyone hates to work with.

1
dev01 1 point ago +1 / -0

No, I'm not. My entire team loves me.

1
Artymisfoul 1 point ago +1 / -0

Sql injection is easy to avoid. Would not hire you fwiw.

1
dev01 1 point ago +1 / -0

I'm a veteran. The chance that I would make that mistake is next to zero, but I'm not going to attack junior devs for it, or fire them. It's more likely that I would refuse to work for you.