Hacker News new | ask | show | jobs
by sumeno 2975 days ago
This only works if you automate every possible code path. If you're logging passwords during some obscure error in the login flow then an automated login very likely won't catch it.
1 comments

True, but it is more effective than doing nothing.
But it's not a choice of doing this or nothing. It's a choice of doing this or something else. That something else may be a better use of your time.