• 1 Post
  • 117 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle

  • There are a couple that come to mind.

    Definitely the worst, a C# .net mvc application with multiple controllers that were 10s of thousands of lines long. I ran sonarqube on this at one point and it reported over 70% code duplication.

    This code base actively ignored features in the framework that would have made things easier and instead opted to do things in ways that were both worse, and harder to do. For example, all SQL queries were done using antiquated methods that, as an added benefit, also made them all injectable.

    Reading the code itself was like looking at old school PHP, but c#. I know that statement probably doesn’t make sense, but neither did the code.

    Lastly, there was no auth on any of the endpoints. None. There was a login, but you could supply whatever data you wanted on any call and the system would just accept it.

    At the time I was running an internal penetration test team and this app was from a recent acquisition. After two weeks I had to tell my team to stop testing so we could just write up what we had already and schedule another test a couple months down the line.













  • When I was in university, I learned that I made more money as a level one support guy at the tiny MSP I worked at than my professor who had multiple awards, papers, patents, and was also some kind of bouldering champion apparently. He was an awesome person and a firm lesson that the amount of money one makes should never be used to measure the worth of a person. Also that teachers need to be paid like, a hell of a lot more.

    Actually that reminds me of another guy I know. I spent a few years working at a GameStop and my store managers dream was to be a history teacher but he would have had to take a significant paycut in addition to getting a lot more schooling and certifications. Last time I ran into him though he told me he’d done it and I’ve never seen him happier.