Please tell me that the people writing this PHP abomination have *nothing* to do with the people developing your hardware tokens. Please. Maybe I should really start looking into alternative products...
-
-
Show this thread
-
Seriously, how incompetent do you have to be to not only write code like this, but also *once the bug is found, completely fail at educating yourself as to what the correct, sane, safe way to fix it is*? I might excuse lack of knowledge, but not the utter inability to learn.
Show this thread -
Seriously, this incident raises *serious* questions about the quality of development at
@yubico. It might be an isolated problem, but how did this mess slip through the cracks? Who reviewed this code? Does an entire team at Yubico think this is okay? Who hired them?Show this thread -
Do the same standards apply to every other team at
@yubico? How do we know this isn't a pervasive problem? Are there any companywide standards on code quality? Is there even a security team dedicated to auditing stuff in general? HOW DID THIS HAPPEN?!?Show this thread -
Btw, someone joked about http://php.net having this as the correct solution, and, well. But "knowing better than http://php.net " is definitely a prerequisite to be in the security business writing PHP. Or just don't write PHP.https://twitter.com/marcan42/status/1089238169839489025 …
Show this thread -
OMG IT'S STILL BROKEN. THIS IS HOW THEY'RE SANITIZING URLS FOR INSERTING INTO SQL QUERIES $ echo "<?php echo filter_var('http://inject/\'', FILTER_VALIDATE_URL);" | php http://inject/' AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Show this thread -
Okay, get this. The fix in question? It was co-authored by 5 Yubico employees and merged (and hopefully reviewed) by a 6th. At least 6 Yubico employees do not know about prepared statements. https://github.com/Yubico/yubikey-val/pull/59/commits/d0e4db3245deb5ce0c8d7d26069c78071a140286 … I am in shock.
Show this thread
End of conversation
New conversation -
-
-
"security" vendor
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Wooow holy shit
@Yubico fix that!Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.