this post was submitted on 03 Oct 2025
547 points (98.9% liked)

Programmer Humor

26703 readers
2694 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] user224@lemmy.sdf.org 112 points 23 hours ago (1 children)

Stop over-engineering shit, just do everything client-side like McDonald's: https://bobdahacker.com/blog/mcdonalds-security-vulnerabilities

[–] passepartout@feddit.org 109 points 23 hours ago (1 children)

My friend who helped me research the OAuth vulnerabilities was let go for "security concerns from corporate"

Good old shooting the messenger.

[–] ZoteTheMighty@lemmy.zip 11 points 20 hours ago (1 children)

I mean, they were an employee who was exploring security vulnerabilities with a non-employee who has a blog. I would have fired them too.

[–] passepartout@feddit.org 12 points 20 hours ago

It is indeed a very risky move without a lot to gain for him personally. But I could guess McDonald's would have forced him to ignore it and shut up about it if he disclosed this to the higher ups himself, in which case I would have gladly left myself instead.