By not building this yourself and instead outsourcing the work to India, to people that work for 4.00$/h
And I'm not blaming the person that has to work for this little cash for delivering shoddy work like this.
It's obviously not foolproof, but it's a good effort.
A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.
No really this is unacceptable for a professional, it’s even bad for an amateur.
If your processes are so insecure that a little tired breaks your whole company you done goofed.
Also bizarre to frame this as “unacceptable behavior”, as if whoever is involved was in some way aware of their mistake and/or would say “this is acceptable behavior!” when confronted with it or something.
This is unacceptable behaviour for a professional in my eyes.
The person I replied to understood it as “piling on more and more agile bs” but IMO that was just bad faith so I ignored it.
You need both - processes that are lightweight but solid where it matters - operators who give a shit
But if they have five security processes that each has a 99% chance of catching a bug, that's still a 1-in-10,000 chance that something will slip through. And I'd wager that a16z has more than 10,000 "components" that goes through those processes.
additionally, i didn't realize there are tools to automatically discover unreferenced subdomains like this. i would have just assumed security by obscurity
I've put internal sites behind AWS ALB's plugged into an OIDC provider[1] (Google), which works well.
1: https://docs.aws.amazon.com/elasticloadbalancing/latest/appl...