• 0 Posts
  • 3.47K Comments
Joined 2 years ago
cake
Cake day: June 10th, 2023

help-circle

  • A program that HR had built so that all employees could they their payment receipts online

    The username was the companies’ email address, the password was a government personal id code that you can lookup online, a don’t change, and you can’t update the password to something else.

    So I told the director of HR this was a bad idea. She told me I was overreacting until I showed her her own receipt, then she finally understood that this is a really fucking bad idea.

    Okay, so now she out me in charge of debugging that program.

    So I setup a meeting with the director of the company they hired, he came by with the developer: a 21 yo girl who I think hadn’t finished college yet. Great start! Apparently it was her idea to do the authentication like that so that explains a few things.

    So we dive in to the code.

    First of all, the “passwords” were stored in blank, no hashing, no encryption, nothing. That wasn’t the worst.

    For the authentication she made a single query to check if the user email existed. Of that was true, then step two was a second query to see if the password existed. If that were true, the email had been authenticated.

    So let’s say, hypothetically, that they had actual passwords that people could change… I could still login with the email from anyone, and then use MY OWN password to authenticate.

    This just blew my mind so hard that I don’t think I ever fully recovered, I still need treatment. The stupidity hurts


  • Wanting: tangent rant incoming about the site, not the article.

    JFC, what a horrible source, that site is cancer

    We value your privacy

    Yeah, that is a lie

    We and our partners store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised advertising and content, advertising and content measurement, audience research and services development. With your permission we and our partners may use precise geolocation data and identification through device scanning. You may click to consent to our and our 1540 partners’ processing as described above. Alternatively you may click to refuse to consent or access more detailed information and change your preferences before consenting.

    Please note that some processing of your personal data may not require your consent, but you have a right to object to such processing.

    Well fucking A, I have the right to object, but you’ll do it anyway

    Great to know that you and your 1540 fucking partners all together respecty privacy, i feel so much fucking better already!

    And mind you, this shit is the best we can get with the gdpr. Without that, it would be a hundred times worse than this.

    But okay, let’s reject everything and try to read the article, shall we? Read the intro paragraph, okay, scroll down a little to read the next and boom I now have a search bar covering half of my page? That’s weird, where did that come from? It’s blocking literally 50% of the page, I can’t read shit. How can I get rid of this? Oh, a close button. Let’s naively close this, naively because we already know better but anyway, click… Aaaaaaand it was a fucking ad. Okay go back, reload page, scroll down aaaaand half the page blocked with another ad

    So as you might have figured, this browser didn’t have an ad blocker (using Lemmy connects internal browser here) andr the site is completely and 100% useless, I can’t read it on a mobile device. So why even bother, then?

    I’ll be adding themirror to my permanent block list right now, I won’t ever be able to see anything from that site ever again. I suggest you all do the same and that we add themirror to a list of banned sources for this sub or, better, this instance.

    I’m so SO sick and tired of the crap that is now the internet. I gettit, these guys too need to earn a living, but there are better ways to set this up.

    Let’s make a world wide independent foundation funded by all governments and that one can pay news organizations to write news. The only rule should be “be independent and truthful”. This is just a single dumb example, I’m sure there are even better ways but FFS, anything is better than this shit

    I’m getting to the point where I think I’ll build a web scraper that will just take out the text, maybe a few relevant images, and the render that into a page that shows just that. I know a few sites that can already do that but I’d like something for myself, just self hosted or something.

    Yes, it’s the middle of the night and yes, I cannot sleep and yes, this pisses me off because I just wanted to read some news to relax but instead I have to furiously rant because these fuckers again didn’t know that enough should be enough

    /Rant


  • Again

    Prohibit billionaires

    Cap all netwoths at 10-20 million dollars per person, tops.

    Companies should not be worth more than 1 billion dollars, cap it.

    Anything over that has automatically 100% go to taxes

    Well end up with -instead of one trillion dollar compant- tens of thousands of centillion dollar worth companies, you know, those that aren’t too big to fail and that won’t need bailouts

    Well end up with a government that gets so much tax income that it can afford free education, free healthcare, hell, UBI even.

    Noone will be super rich and or powerful ever again, no one will be able to usurp all resources for themselves.

    Humanity spent 2000 years on perfecting the “0.1% must get as Uber rich as possible” and we got it down to an art to concentrate as much wealth as possible with as little people as possible. It is NOT normal, it is NOT acceptable, ajf it has to stop NOW! It’s destroying our world, literally, as these assholes are the main drivers behind climate change.

    Here I am making sure to use as little water as possible and all of my life long work gets thrown into he garbage because miss multimillionaire needs to do grocery shopping with her fucking private jet.

    While on this bandwagon, ban all private jets, even for politicians. Maybe maybe we can keep a few as a sort of air ambulance or something z that should be fine, but all the rest, BAN IT. Same for theega yachts, outright world wide ban.

    It is bizarre to me that most people just act as if all this is perfectly fine and acceptable. There is no right, no reason why anyone should have a higher net worth than (say) 10 million, so why do we allow this to happen in the first place?

    Haven’t we learned anything?