DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

Collapse
 
falonofthetower profile image
Peter Karth

The data from forms filled with precisely the data required for stealing identities (name SSN, address etc), because they were helping people who lost their identity. The data was available in convenient PDF form to the user when logged in. Their data, change the id and someone else's data, pretty much all the data available to any user at all.