|
|
|
|
|
by phillmv
4461 days ago
|
|
The excuse is precisely that there isn't a great, all encompassing framework. Setting up a scenario where everyone has to get everything right all of the time is setting everyone up for a lot of heartbreak. Having bad password management and opening everyone up to CSRF and XSS is not "trivial". They're gotchas, and looking out for gotchas is a waste of everyone's time. |
|
As I said, I'm all for having a great framework, but I would not excuse the mistakes being made here, and I'm simply saying that I believe that my products and my knowledge level benefited by not having one.
> Having bad password management and opening everyone up to CSRF and XSS is not "trivial".
I'm not suggesting everyone should need to be aware of these issues, I'm saying someone on your team should be. And if you're a team of one, be prepared to make mistakes (which will not be limited to the issues outlined here).