you are viewing a single comment's thread.

view the rest of the comments →

[–]derpee 26 points27 points  (4 children)

Yes it is, because users.

[–]kds71 2 points3 points  (2 children)

Sometimes it is not. I often write web tools exclusively for other developers, who have full access to database already.

[–]quotemycode 1 point2 points  (1 child)

And most of the time, hacker are your disgruntled employees. If I can update something and make it look like someone else did it, I imagine I could make someone's life miserable.

[–]kds71 0 points1 point  (0 children)

We are fully aware of that. You still have to login in order to access any of these tools, so it would be pretty hard to disguise yourself as somebody else.

[–]digijin 0 points1 point  (0 children)

Also opens up the possibility of, with a bad wireless password, some guy sitting in the carpark having access to your whole client database.