The Security Bug That Almost Shipped

https://hackernoon.imgix.net/images/2jqChkrv03exBUgkLrDzIbfM99q2-yx822ij.png

Most engineering war stories I’ve heard in my career fall into a couple of recognizable shapes. There’s the outage story: something broke at 3 a.m., the team got paged, the on-call engineer figured it out in some dramatic way, the system was restored, lessons were learned. There’s the heroic-feature story: a team shipped something difficult on an aggressive timeline, somebody pulled a long week, the launch went well.

The story I want to tell isn’t either of those. It’s the story of a vulnerability that almost shipped to production, was caught in the last days of a release, and quietly got fixed. There was no outage. There were no users affected. There was no public postmortem because the issue never became public.

These stories almost never get written down, which is a shame, because the catch-late stories teach things the ship-late stories don’t. The almost-shipped vulnerabilities are the ones that,...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE