Hacker News new | ask | show | jobs
by dasil003 6043 days ago
As someone who worked for an agency supplying a few hundred realtors across 6 different MLSes with web development, I can also testify to the utter technical incompetence of at least one of the major suppliers (who shall remain unnamed) of back-ends for hundreds of MLSes.

I noticed a bug in our CSV import one day and I discovered that they were quoting, but not escaping quotes in any way. Thereby making it possible for any realtor to inject whatever the data they wanted for anyone else's listings either before or after theirs (depending on how the data importers resolved conflicts).

This was a huge security hole affecting probably hundreds of thousands of listings nationwide, and you know what their developer support said to me? They actually sent me a suggested workaround tailored to the particular instance of corrupted data that I had encountered. When I explained to them the ramifications of this to their business they simply ignored me.

Damn I'm glad I got out of that game.

1 comments

"Hello, this is the front desk."

"Hi, I'm in room 118 and I smell smoke."

"We'll send up some air freshener right away, sir."