Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps I'm dating myself a bit here, but there was a time when there was no such thing as an "e-commerce app" and no wi-fi to eavesdrop on. Black hat hacking has evolved also, so although some techniques have always been possible, new vectors have opened up over time as they are discovered and disseminated, and I would suggest the corresponding knowledge burden needed to enter the arms race for a developer is higher now. Also, the tools have evolved in such a way that the barrier to entry is lower and lower. For example, FireSheep.


Of course there was a time before ecommerce apps. That would probably explain why I was talking about the very first perl cgis. While there's a lower barrier to entry for people to exploit security holes, there's also far more targets. Automated tools to go around exploiting the latest holes in "insert shitty PHP app here" aren't an issue for web developers who are writing their own apps. The security issues that impact web developers are the same as they have always been for all kinds of developers, input filtering, escaping output, etc. Web developers have always needed to understand basic security issues, it is just that 99% of web developers historically have been completely incompetent. This does not appear to have changed recently.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: