Hello, I'm web developer from a Turkish university IT department.
First of all i must tell my opinion about hacking web sites: if your site is hacked, find the hacker and give him to justice. Propably we agree about this. But, also fire your developer if the vulnerability is too childish.
And probably we don't agree about this subject. Because every developer i talked about this issue said: "this things happen... we cant predict every hacking method before it happens." etc.
But the root of the problem is a lot of developers see security as "add-on feature" instead of system feature.
I see a lot of SQL code like this, every day: "SELECT * FROM users WHERE user_id =" . $_POST['id'];
Trusting user input without validating, sanitization? And this brings us to another problem:
Universities are government organizations and the manager are chosen by "governmental standarts" which are "none".
A lot of IT department managers aren't coming from IT background. Some of them are just written some sort of statistical fortran program while in graduate school. If you have to write a complex CMS and want 3 months to do it, you probably have to do it just in 1 month. And the answer for your "3 months request" is: "X said a program like this can be written in just under 1 month". And x is some intern student.
And this brings us to another problem: Intern students...
Turkish university IT departments use students. I'm ok with that. I started as a student too. But, if you are "interested in computers", this is ok to get the job. And after that you are assigned with writing essential LOB software or even staff payment software. And you are writing "WHERE $_POST['id']"....
I'm bored... That's it for now. Thanks for reading.
Sorry guys but bad news here: when a open source project gets a back up from a big company, it's not open source anymore.
actually, it is open "source" but thats it. only the source is open. the "fork" arguments is also useless. if i fork android source, nobody will use it. nobody. because it's not "google" anymore.
remember the "window controls on the left site" debate with ubuntu? everybody was talking against it but it happened "shuttleworth's way".
After "I'm not a group of hacker, I'm single hacker with experience of 1000 hackers, I'm single programmer experience of 1000 programmers," part, i stopped reading.
It's not a "news" for me. Because i live in Turkey. In our country Youtube is banned since 2008. And people got used to it. They were always like that: first month everybody says "this is not acceptable, i'm as mad as hell and i'm not gonna take this anymore" but after a couple of weeks everybody gets used to it. no problem. is youtube banned? yes. try facebook videos.
it's like iran but nobody recognizes it. everything is banned or restricted but they are taking no action against governemnt.
can't get alcohol, can't kiss girlfriend in a park or even hold her hand etc. but nobody complains about it.
Before reading the post, i was thinking "dude, this is a troll post."
after the first 5 paragraphs i was thinking, "dude, he has got a point. i think TL;DR is : 'tools doesn't make you a good programmer use whatever you want."
but after the "dojo" section, now, i'm thinking "this blog post is for trolling."
there is no god damn one tool to make you a good programmer. not a web framework, not a ide or anything. the tools are nothing to do with your skills.
you have to learn programming without program anything at the early stages. learn programming fundamentals, algorithms, design patterns, best practises and so on.
i'm not giving a shit about which tool you use. if you are using MongoDB because "it's new and everybody talks about it" i will kill you. use a tool only if it does the job.
yes, windows has a lot of virus. ok, we get it. we get it for over ten years. every year i hear "this year linux will be on every desktop". But it never happened. Just be more realistic please.