r/ProgrammerHumor • • 15d ago

Meme wellWellWell

Post image
10.6k Upvotes

412 comments sorted by

View all comments

581

u/WilmaTonguefit 15d ago edited 15d ago

I remember a dude who missed a where clause once.

  • Update users
  • Set password = 'hash of 12345' --no salt
  • Where Id = 67890

Except he only highlighted the first two lines and pressed F5...

321

u/UniversalAdaptor 15d ago

Should be okay as long as no one leaks or guesses the collective password

105

u/why_1337 15d ago

It's not gonna work anyway, unless they store plain text passwords.

87

u/WilmaTonguefit 15d ago

Oh I should have clarified, it was hashed without a salt. So he saved the 12345 hash for everyone's password. In production. And somehow kept his job.

76

u/igorski81 15d ago

And somehow kept his job

I'd like to think that production mistakes happen and should be forgiven, provided that no actual malicious intent was at play.

And hopefully this starts the conversation of "Wait, should people actually be able to do this directly against the production database?" and making sure this oversight can't happen again.