Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #4272
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: Lilupophilupop |
| Date | 2012-01-07 16:02 -0500 |
| Organization | A noiseless patient Spider |
| Message-ID | <jeabsn$6m0$2@dont-email.me> (permalink) |
| References | <9mqrbsFs13U1@mid.uni-berlin.de> <je9ghb$bvv$1@dont-email.me> <je9v9o$hit$1@news.albasani.net> <9mrf20Fm65U1@mid.individual.net> |
On 1/7/2012 12:52 PM, J.O. Aho wrote: > Thomas Mlynarczyk wrote: >> Jerry Stuckle schrieb: > >>> Nothing new here - it just shows there are a lot of programmers out >>> there >>> unconcerned with security. >> >> Indeed. But I don't understand why this is so. After all, we're not >> talking >> about the personal homepage of some newbie showing pictures of his dog >> and >> favourite cookie recipes. The problem exists also (if not especially) >> with >> real big professional sites, even sites where security is paramount >> (online >> banking), run by people who should have more than enough money to pay >> competent, security-aware programmers to do the job properly. I just >> don't get >> it. > > The big issue is "maximize profit" and "finish on half the required > time", when you have those two things as the main mantras, then > everything will be crap, not just web sites and their security, but > things like cell phones which won't hold more than max 3 years, crappy > health care and insurances which don't cover anything at all. > > True to a big extent, J.O. But proper security practices are cheaper up front than trying to go back and fix the problem later. I think a much bigger problem here is there are a huge number of programmers who don't understand proper security practices. For instance, they think the only way someone can POST data to their site is from another page on their site, and validating data with javascript before it is sent is sufficient security. Nothing could be more wrong. -- ================== Remove the "x" from my email address Jerry Stuckle JDS Computer Training Corp. jstucklex@attglobal.net ==================
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-07 13:15 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 08:15 -0500
Re: Lilupophilupop Thomas Mlynarczyk <thomas@mlynarczyk-webdesign.de> - 2012-01-07 18:27 +0100
Re: Lilupophilupop "J.O. Aho" <user@example.net> - 2012-01-07 18:52 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-07 16:02 -0500
Re: Lilupophilupop "Peter H. Coffin" <hellsop@ninehells.com> - 2012-01-10 18:31 -0600
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-11 09:29 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-11 08:42 -0500
Re: Lilupophilupop Erwin Moller <erwinmollerusenet@xs4all.nl> - 2012-01-11 15:23 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-07 14:28 +0100
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-07 16:13 +0100
Re: Lilupophilupop Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2012-01-07 18:03 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-07 20:34 +0100
Re: Lilupophilupop "M. Strobel" <sorry_no_mail_here@nowhere.dee> - 2012-01-08 14:53 +0100
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 15:27 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 10:00 -0500
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 18:29 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 15:49 -0500
Re: Lilupophilupop Gregor Kofler <usenet@gregorkofler.com> - 2012-01-08 22:59 +0100
Re: Lilupophilupop Jerry Stuckle <jstucklex@attglobal.net> - 2012-01-08 17:38 -0500
csiph-web