Story challenge: What’s your funniest or most relatable security moment? Without breaking NDA, of course!

#AppSecThursday #talkAppSectome

@SheHacksPurple I’ll bite. Engineer working on a CRUD interface for customer details didn’t check login against session variables. Anyone with login from lowest security level to admin could see all customer details. DBA wasn’t fussed with encrypting credit and contact details.
@peterrenshaw omg!!!! Wowza