On Wed, 2003-10-01 at 22:57, Ed Wilts wrote:
> On Wed, Oct 01, 2003 at 06:32:04PM -0500, Bret Hughes wrote:
> > Do I dare say this out loud?  I wonder what would happen if you
> > submitted a modified price order?  Don't try it because it is probably
> > illegal but I have a sneaking suspicion that the billing price tracks
> > through from there.
> 
> There is a human being on the other end, so you won't get a price break.
> You'll just be wasting their time and yours.
> 
> Not everybody is a perfect programmer.

Obviously.  But that doesn't excuse blatant errors like this from a
professional developer working for a company with a serious online
presence.  This is not a case of having to be a "perfect programmer" to
prevent external influence of your content.  This is web-dev 101.

If they're this bad, I have no reason to trust the rest of their site. 
Let's sum up some of their recent bonehead decisions:

- Simple form injection through URL tampering
- Inability to delete user accounts in RHN
- Expiration of up2date certificates
- Questionable perl-suid package dependency for Perl errata
- Lack of SOHO-style errata support (I know, be patient...)

Ok, I'm off my soapbox.  But that felt damn good.  ;-) 

-- 
Jason Dixon, RHCE
DixonGroup Consulting
http://www.dixongroup.net


-- 
redhat-list mailing list
unsubscribe mailto:[EMAIL PROTECTED]
https://www.redhat.com/mailman/listinfo/redhat-list

Reply via email to