Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today.
This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
In TFA there is no single issue of actual things that web developers could be blamed for.
CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.
All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.
Comments
Web Developers, please follow every best practice, I’m begging you
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
Who do we call? CTOs I guess.
Ghostbusters!
Who made the website?
Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today.
This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
I had marketing close their godaddy account and centralized the domain request flow to the ops team, for security reason.
One of the best workflow changes ever implemented, didn't even need to become CTO.
Who designed the customer flow?
In TFA there is no single issue of actual things that web developers could be blamed for.
CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.
All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.