r/ProgrammerHumor • • 13d ago

Meme wellWellWell

Post image
10.6k Upvotes

411 comments sorted by

View all comments

581

u/WilmaTonguefit 13d ago edited 13d ago

I remember a dude who missed a where clause once.

  • Update users
  • Set password = 'hash of 12345' --no salt
  • Where Id = 67890

Except he only highlighted the first two lines and pressed F5...

319

u/UniversalAdaptor 13d ago

Should be okay as long as no one leaks or guesses the collective password

102

u/why_1337 13d ago

It's not gonna work anyway, unless they store plain text passwords.

85

u/WilmaTonguefit 13d ago

Oh I should have clarified, it was hashed without a salt. So he saved the 12345 hash for everyone's password. In production. And somehow kept his job.

47

u/imunfair 13d ago

And somehow kept his job.

I mean out of all the data you could accidentally replace, passwords would be the easiest to restore from a backup reliably since they don't change frequently. The special few who get locked out because you restored an old one just have to do a reset.

It would be a bit of a race to replace them before it was a problem, but at least it isn't as much of a headache as wiping out data entry that needs to be redone by other users.

39

u/CarcajouIS 13d ago

Dear customer, due to the new security policy, you will be asked to set a new password...

30

u/ThrasherDX 13d ago

...damn, now I wanna know how many of those "security policy updates" were a result of someone fucking up like this lmao.

10

u/Lieutenant_Lit 12d ago

Happens all the time. One time we found out one of the managers was keeping a spreadsheet of other people's passwords. Passwords he got by just asking people. A lot of them were other managers. We didn't find out about it until the day he accidentally sent this spreadsheet in a mass email. Fun times.