Post B4iCe0gHawTXhlmSmW by steter@mastodon.stevesworld.co
 (DIR) More posts by steter@mastodon.stevesworld.co
 (DIR) Post #B4iCe0gHawTXhlmSmW by steter@mastodon.stevesworld.co
       0 likes, 1 repeats
       
       Who puts API keys in javascript meant for production? Well, an LLM might. Developers lacking common sense might. Maybe don't put API keys IN YOUR CODE MEANT FOR BROAD DISTRIBUTION so this won't happen, eh?A side issue here is the lack of competent QA. These are not small companies. Not one character of developer code should be accepted without first testing it, and without scanning it for potential oversights for exploit, like leaving API keys in the javascript.🎶 Oh, yeah,I'm a back door man.🎶 With the advent of LLMs, we can't blame the developers. It's on everyone ABOVE the developers, starting with QA and middle management. Deadlines < Breeches. Always. Take a little more time to get clean releases, please.https://social.linux.pizza/@MichaelRoss/116304507582184926RT: https://social.linux.pizza/users/MichaelRoss/statuses/116304507582184926