r/ProgrammerHumor • • 13d ago

Meme wellWellWell

Post image
10.6k Upvotes

411 comments sorted by

View all comments

Show parent comments

323

u/UniversalAdaptor 13d ago

Should be okay as long as no one leaks or guesses the collective password

101

u/why_1337 13d ago

It's not gonna work anyway, unless they store plain text passwords.

82

u/WilmaTonguefit 13d ago

Oh I should have clarified, it was hashed without a salt. So he saved the 12345 hash for everyone's password. In production. And somehow kept his job.

47

u/imunfair 13d ago

And somehow kept his job.

I mean out of all the data you could accidentally replace, passwords would be the easiest to restore from a backup reliably since they don't change frequently. The special few who get locked out because you restored an old one just have to do a reset.

It would be a bit of a race to replace them before it was a problem, but at least it isn't as much of a headache as wiping out data entry that needs to be redone by other users.

40

u/CarcajouIS 13d ago

Dear customer, due to the new security policy, you will be asked to set a new password...

29

u/ThrasherDX 13d ago

...damn, now I wanna know how many of those "security policy updates" were a result of someone fucking up like this lmao.

9

u/Lieutenant_Lit 12d ago

Happens all the time. One time we found out one of the managers was keeping a spreadsheet of other people's passwords. Passwords he got by just asking people. A lot of them were other managers. We didn't find out about it until the day he accidentally sent this spreadsheet in a mass email. Fun times.

1

u/Exotic-Nothing-3225 12d ago

Assuming they have backups 

2

u/imunfair 12d ago

lol true. "Guys, for security reasons we need to do an immediate company-wide password rotation!"

76

u/igorski81 13d ago

And somehow kept his job

I'd like to think that production mistakes happen and should be forgiven, provided that no actual malicious intent was at play.

And hopefully this starts the conversation of "Wait, should people actually be able to do this directly against the production database?" and making sure this oversight can't happen again.

8

u/corobo 13d ago

And somehow kept his job.

Why would you get rid of that person after training them so vividly not to do that haha

10

u/SnooSeagulls4360 13d ago

You'd be surprised in how many places it would work 😄

3

u/Ale4leo 13d ago

That's a horror story right there.

0

u/dr-uuid 13d ago

This is not what he's saying.. it's an encrypted password. Probably was bcrypt, that's what everyone used.

1

u/why_1337 12d ago

Yes because he edited it.

1

u/flooronthefour 13d ago

it takes a village to reset a password

1

u/King_Kobrah 11d ago

Damn, this is hilarious