• 2 Posts
  • 491 Comments
Joined 2 years ago
cake
Cake day: June 10th, 2023

help-circle

  • A program that HR had built so that all employees could they their payment receipts online

    The username was the companies’ email address, the password was a government personal id code that you can lookup online, a don’t change, and you can’t update the password to something else.

    So I told the director of HR this was a bad idea. She told me I was overreacting until I showed her her own receipt, then she finally understood that this is a really fucking bad idea.

    Okay, so now she out me in charge of debugging that program.

    So I setup a meeting with the director of the company they hired, he came by with the developer: a 21 yo girl who I think hadn’t finished college yet. Great start! Apparently it was her idea to do the authentication like that so that explains a few things.

    So we dive in to the code.

    First of all, the “passwords” were stored in blank, no hashing, no encryption, nothing. That wasn’t the worst.

    For the authentication she made a single query to check if the user email existed. Of that was true, then step two was a second query to see if the password existed. If that were true, the email had been authenticated.

    So let’s say, hypothetically, that they had actual passwords that people could change… I could still login with the email from anyone, and then use MY OWN password to authenticate.

    This just blew my mind so hard that I don’t think I ever fully recovered, I still need treatment. The stupidity hurts


  • So-called “bossware” lets managers keep a close eye on employees’ activity, tracking everything from knowledge workers’ website visits to the gait and facial expressions of those involved in more physical activities.

    It would be so hard to not furiously masturbate to the camera just to shock the fuck out of those assholes.

    Anyways, this is sick behavior. If you have so little trust in your employees, than you are the problem, not them












  • Google: "Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn’t verified.

    And we will NEVER trust you again because we know you’ll retry this next year or so in a few smaller steps that all have cutesy innocent names that are supposed to lull us in a false sense of security

    Fuck Google, stop paying them for anything, stop using their services wherever possible.