Elektrine lite

← Feed

@joby@hachyderm.io

Post #4235751

2026-07-24 19:43 UTC

@r_alb@mastodon.social Yup. I build web apps at a university and one of my central tenets over the years has always been "we can't accidentally leak what we don't have." Collecting RSVPs for an event, the form has fields for phone number and mailing address? Have we ever once used that information for anything? No? Gone from the form. Why were we even doing that? The list of graduates includes students with privacy flags on their accounts and the site filters them out at runtime? What happens if somebody breaks that someday? Now we've leaked the names of all these students who are hiding from stalkers or whatever. That's a disaster. Why not just delete those records from the database and filter them out during the import process entirely so our site cannot possibly even know they exist in the first place?

Replies (0)

No replies.