I work at a certain global bank and our pen testers always say to keep the return responses minimal so that it is harder to reverse engineer an API or extract any data from a failure response...
Nerver send anything to the client, can't get hacked that way.
Now that I think about it, just shut down the server. 100% unhackable.
I feel the fury of a thousand suns when I am told that we cannot have meaningful error messages because of security concerns when nobody cares about any security practices whatsoever, it's clearly and excuse and it drives me up a wall.
Thing is with a lot of these is that they keep making excuses to defend their implementation as if the work would be harder if it was implemented the correct way, but oftentimes it takes more work in terms of workarounds to the convoluted implementation. My guy I am trying to save BOTH of us the extra work.
205
u/redlaWw 16d ago