DEV Community

Discussion on: Never Trust User Input

Collapse
 
_garybell profile image
Gary Bell

That's a great story, made me chuckle.

I've done a few system audits for clients. This particular one we then quoted for a secure rebuild (I worked for a custom software house), but they declined and took our findings to another company. I did one which was for parents to track their kids on their school journey in real time. It was a couple weeks from launch and we discovered such serious issues that we told them if they went live with it, we'd have an obligation to break our NDA and report them to the ICO for a data breach. I think they went out of business a couple months later.

Collapse
 
mcastellin profile image
Manuel Castellin

Wow, is that for real?! No excuses for taking security lightly with the kid's location! Unbelievable how people just don't care..

Thread Thread
 
_garybell profile image
Gary Bell

They offshored the development to the cheapest bidder. It cost them their entire investment and business. I don't think the business owners realised how bad it was until we showed them.