Jesus our security infrastructure people are stupid. They are telling us to secure a service that we don’t want accessible directly by the role “member” setup to be accessible by “member”. All because they “don’t want us changing identities in the middle of a chain of web service calls”. They are like “don’t worry, the fire wall keeps them out”.

That’s like saying “here’s the key to the bank vault, but you won’t ever get past the security guards so it’s okay that you have it.”

I swear this company is stone stupid.

Add Comment