Just yesterday I found out that a multimillion euro corporation still uses Http (not https) rest end points, with the only basic authentication mechanism...
It only provides data to sales and inventory management, so I'm guessing it's not f*ing critical enough x.x

  • 4
    Do a mitm and prove them wrong I guess
  • 3
    @myss I do flirt with the idea, but decided to let them know instead, hoping they will fix it. (> press X to doubt.png)
  • 1
    Random inventory numbers go!
