How does a company whose only job is security screw that up so badly?
How does a company whose only job is security screw that up so badly?
One of the points of the article is that documentation isn’t enough: one cannot allow callers to misuse one’s API.
While I don't have any answers to this, I've realized that it's an ideal showcase of why fuzzy testing is useful.
On the other hand, I'm not a security developer at Okta.
Silently truncating the data is about the worst way to deal with it from a security standpoint. No idea why that decision was made back in the day.
An error code is risky.
Apps crashing with assets is awfully, but at least it screams at your when you failed to read the docs, target than incorrectly storing users data for the rest of time.
Like getting an input that is too long? :)
I think a library asserting that the preconditions of its arguments are true is fine.