That’s like selling a car without preinstalled seat belts and then saying it is the responsibility of the driver if they take it on the road like that. It’s technically true, but it’s sort of missing the point.
That’s like selling a car without preinstalled seat belts and then saying it is the responsibility of the driver if they take it on the road like that. It’s technically true, but it’s sort of missing the point.
> I do have concerns when 10gen explicitly targets junior developers ... What [Eliot, MongoDB CTO] says makes sense say 20 years ago, but with 25% of new software engineers coming from coding bootcamps with non-engineering backgrounds, I worry that defaults matter ever more in dev tools (and even seasoned engineers may mess this up, if they’re coming from a database with different defaults). We discussed analogies like seat belt lights versus the responsibility of passengers to know better. He also argued that waiting to get all this right - not just auth - would impact database innovation, while I think there’s a balance that gets us a lot of the low hanging fruit (like security).
This is unnecessarily elitist: I’ve seen no difference in security awareness based on anything other than specializing in security, and even then it can be surprisingly blinkered.
But I agree that no matter the program, security best practices are rarely taught.
If I have to use a vast number of tools, not only can't I be an expert in all of them, I can't even dedicate 5% of my attention to each one of them. Or really, to any of them. Because if I do, then I have nothing left to fulfill my job description. I'd just be curating a list of third party code all day long.
We either need to back away from the 'npm install' model or we need to really start thinking about our libraries as cattle. Which means they all have to behave in a predictable fashion or we cull them from the herd.
You can't have it both ways. We can't use peer pressure to stop people from writing their own (NIH), and then blame the victim when tools behave in surprising ways. The safeties need to be on by default, and only a few things in our lives can be so dangerous that we require special training to use them without killing ourselves. We only have space for a handful.
We need to develop the humility to accept that our module should be boring to the people using it, rather than a special snowflake. Take pride in the utility, not the notoriety.
"Well just don't shoot yourself or the wrong people silly!"
Dude that is not what happens in the real world!
Fun fact: one of the bartenders at my old watering hole was playing with the "bar gun", flipping the cylinder closed by flicking his wrist, and shot a round into the wall. Luckily I wasn't there that night because accidental discharges are a beatable offence.
If someone shot a round into a wall at a bar, it would be more than a beatable offence for me.
The two most popular handgun lines in the US, the Glock[1] and the M&P[2], don't have what a laymen would consider a safety. The Sig P250[3], of CounterStrike fame, has no safety of any kind whatsoever.
[1] https://en.wikipedia.org/wiki/Glock [2] https://en.wikipedia.org/wiki/Smith_%26_Wesson_M%26P [3] https://en.wikipedia.org/wiki/SIG_Sauer_P250
(You should NEVER put your finger on a gun's trigger unless you intend to fire it. This is taught in all good gun safety courses.)
I doubt the original commenter new the difference, and was most likely referring to manual safeties.
There's internal safeties to stop it from discharging if you drop it, but there's no safety to stop you from pulling the trigger and discharging a round.
https://www.sportsmansoutdoorsuperstore.com/products2.cfm/ID...
Sell thing where they say "well don't do that" doesn't make much sense in some cases.
To me this sounds like the hardware store selling saws, an uneducated consumer coming in and buying one and then going home and cutting their finger off and complaining that the hardware store should sell safer saws.
It's your responsibility to educate yourself on proper and safe operation of your tools.