|
|
|
|
|
by cremp
2908 days ago
|
|
I don't think it is about compliance or security at all; just developers that aren't competent. > 2.6 million plaintext passwords Anyone who is actually competent knows hashing at a minimum; and it costs nothing to implement, both time and money wise. All of this, because Johnny over here read a tutorial on how to make your own app. The downside of development is that, you do get these people who 'stain' the title, because they just read it and followed blindly instead of actually learning. |
|
A few weeks ago I found out a newer hire (at senior level) decided to build his own auth system, because the current one, "doesnt work". It doesn't work because it doesn't allow our employees to handle customer passwords. Even with high turnover, some people don't understand why that is essential.
When simplicity fights security in a corporate setting, simplicity nearly always wins. The exception is when an executive is security savvy and isn't a push over to their peers.