BlackNeon.net
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
mudkip@lemdro.id to Programmer Humor@programming.devEnglish · 9 days ago

Apple forgot to disable production source maps on the App Store web app

files.catbox.moe

message-square
11
link
fedilink
4

Apple forgot to disable production source maps on the App Store web app

files.catbox.moe

mudkip@lemdro.id to Programmer Humor@programming.devEnglish · 9 days ago
message-square
11
link
fedilink
alert-triangle
You must log in or # to comment.
  • bleistift2@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    1
    ·
    9 days ago

    Depending on the exact level of stupidity clinging to the judge on that day, some jurisdictions might consider this “hacking.”

    One case from the states that was luckily dismissed: https://uk.pcmag.com/security/136282/missouri-gov-goes-after-reporter-who-found-shockingly-bad-flaw-in-state-website https://www.vice.com/en/article/this-is-the-hacking-investigation-into-journalist-who-clicked-view-source-on-government-website/

    • CHKMRK@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 days ago

      Germany for example. There was just the Modern Solutions case and the ruling was that using a hex editor to get hardcoded MySQL passwords from a binary is considered hacking

  • Mr. Satan@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    9 days ago

    Security through obscurity is not security. I see no reason why source maps should be unavailable.

    • entwine@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      9 days ago

      Because source maps show how shitty your organization’s code and overall engineering practices are.

      • Phoenixz@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        9 days ago

        Ding ding ding

        Open source code is usually quite nice and well done because money pressure is way less of an issue and everyone knows people will be looking at your code

        • ulterno@programming.dev
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 days ago

          If you look at the casual code that I have shamelessly made public on my GitLab, that might change your mind on that.

    • mack@lemmy.sdf.org
      link
      fedilink
      arrow-up
      1
      ·
      8 days ago

      depends.

      if we’re talking about a personal website nobody will care. if you are a multibillion company and there’s the risk that literally anyone can create a 1:1 clone of your services… yeah that’s a bit of a trouble

      • Mr. Satan@lemmy.zip
        link
        fedilink
        arrow-up
        0
        arrow-down
        1
        ·
        8 days ago

        Omitting source maps doesn’t prevent that.

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      7 days ago

      Payload size

      • Mr. Satan@lemmy.zip
        link
        fedilink
        arrow-up
        0
        ·
        7 days ago

        It was mentioned before. Source map is a comment with an URL. It’s not pulled automatically unless the client has devtools and supports that. It doesn’t meaningfully increase the size of the site for normal users.

        • setVeryLoud(true);@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          7 days ago

          Eh, true. It does clean up the payload, but I agree it’s marginal.

Programmer Humor@programming.dev

programmer_humor@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.64K users / day
  • 3.31K users / week
  • 3.33K users / month
  • 3.4K users / 6 months
  • 1 local subscriber
  • 27.3K subscribers
  • 153 Posts
  • 799 Comments
  • Modlog
  • mods:
  • adr1an@programming.dev
  • Feyter@programming.dev
  • BurningTurtle@programming.dev
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org