Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You are entirely missing the point.

Of course you should know the basics, in fact, you should know everything otherwise what you build will be insecure. But traditionally the 'systems programmers' took care of those details for you and you could write your application in a wonderful trustworthy world. Until ~1992 hacking into a remote system was remarkably hard because there was far less software and that software had been vetted extensively before it was deployed by people who knew what they were doing.

Now it's a free-for-all where everybody with $5 to spare can spin up a VPS and slap some insecure bunch of webstuff on it or cook it up themselves. That's a completely different situation.



It is that in 90ties nobody predicted Internet. Most systems where build with assumption that network is trusted or no network.

Secondly Moor Law consequences where visible after few years. Even MS did not predicted PC boom, everyone now have few computers. Both in terms of performance and availability of hardware we see it massive shift.

It is extreme difficult to add security to system afterwards. In Last Kerberos vulnerability was fixed like last year (Kerberos is used from Windows 2000). Wordpress is still not secure... OpenSSL have something every year.

  > it was deployed by people who knew what they were doing.
It is opposite. These people had no clue that systems they are building will be exposed to internet. Even if they did, it is all written in C on hardware that have very little protection (rowhammer).


I think my point is that SQL injection is at the level application programmers should be worried about.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: