Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Never attribute to malice that which is adequately explained by stupidity"

Some lazy engineer probably added the feature as a remote monitoring/debugging tool with no regard for security because it needed to work before the next big release. Disabling the feature before the next release would probably break all kinds of support and monitoring, potentially leading to instability or them being unable to service failing equipment.



Thankfully not all of us take your approach.

Because you should always assume malicious intent when it comes to IT security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: