DEV Community

Discussion on: What are the worst security practices you've ever witnessed?

Collapse
 
prithajnath profile image
Prithaj Nath

A multi million dollar client once gave one of their vendors access to their internal API by exposing a node directly to the Internet (plain HTTP with port number and all) and whitelisting the vendor's IP address range