Hacker News new | ask | show | jobs
by AmericanChopper 2385 days ago
Even poorly designed business rules create huge number of security issues. The whole stack could be perfectly bug-free and you’d still get those.
2 comments

It can get worse. How about deliberately designed features that are security bugs? I'm looking at Microsoft's "sure, we'll execute any email attachment that the user clicks on, because that's more convenient!". Implementation language wasn't going to save you there...
Credit card numbers as customer identifiers on printed and emailed documents? Seen it.