• ImplyingImplications@lemmy.ca
      link
      fedilink
      arrow-up
      61
      arrow-down
      5
      ·
      7 months ago

      There’s a string stating that the code should not be passed or the employee will be fired. I’d assume this was a test to see if an employee meant to be doing code review was actually doing them. Spoiler, they were not, as OP said they found this in production code.

      • xmunk@sh.itjust.works
        link
        fedilink
        arrow-up
        17
        arrow-down
        4
        ·
        7 months ago

        I’d go a step further and I suspect it’s a peppering string (i.e. fixed string you add to hashes to defeat rainbow tables). I’d really hope it isn’t as you mentioned because gosh that sounds like a toxic workplace if someone is just leaving landmines around purely to get someone fired.

        • skulblaka@startrek.website
          link
          fedilink
          arrow-up
          20
          arrow-down
          1
          ·
          7 months ago

          More like, you know damn well that Jim keeps passing code reviews without reading a line in them, he’s been talked to, still does it, and you need something actionable to prove it so that you can get someone’s ass in his chair who does their job.

          • jcg@halubilo.social
            link
            fedilink
            arrow-up
            12
            ·
            7 months ago

            From the stories I’ve heard from corporate software employees, this does sound like exactly the kind of thing you gotta do to show some manager the guy is buddy-buddy with that they’re actually not doing their job. And even then they didn’t listen.

          • xmunk@sh.itjust.works
            link
            fedilink
            arrow-up
            3
            arrow-down
            2
            ·
            7 months ago

            No, I don’t think so - it’s just a dick move to go out of your way to sabotage someone. If they’re fucking up just visit their existing mistakes - don’t waste time contriving new ones.

            • Reddfugee42@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              7 months ago

              So when TSA sends fake guns and bombs through luggage, it’s not qa, it’s just a dick move to sabotage them?

    • palordrolap@kbin.social
      link
      fedilink
      arrow-up
      5
      arrow-down
      6
      ·
      7 months ago

      My guess is a “solution” to the age-old problem of needing to store a secret in a file that the user can download, thus making the entire system insecure.

      This “solution” appears to be either that the string itself is so outrageous that the user would not believe that it’s the real secret when it is in fact the real secret, leveraging security through obscurity, or else it’s there in place of the real secret that cannot be revealed under pain of death firing, and therefore is accidentally being used instead of that intended secret… so it’s not secret after all.

      Unless they’re doing something incredibly clever to substitute that secret string for the real thing when the time is right and doing it in such a way that the user can’t intercept, someone’s getting fired.

      • dev_null
        link
        fedilink
        arrow-up
        5
        ·
        7 months ago

        No, it’s not. It’s part of React internals that you shouldn’t use because your app will break. It’s a warning for developers using React. It’s not a secret of any kind.