Hi, I've joined a startup a few months ago(with a few dozens employees). A B2B startup which have some very huge clients which you all heard of, multinationals, some parts of governments.<p>It's not critical infrastructure or anything close to that, but we deal with the personal data of pretty important employees of those companies, and have an app installed on their phones.<p>And the "security" culture, seems like the worst you could imagine, I wonder if it's (almost) the norm in the industry or just some bad luck, would love to have your opinions and stories about this topic<p>A few months ago, I found a vulnerability allowing any user(and I do mean ANY user), to login as an admin on our homemade administration space with a simple trick, which would allow them to change almost any "trusted" content that users can see on our app, text, images, videos, links or files that they'll be asked to open/download, delete users, dump a list of all users...<p>Fixing this has been at the bottom of the todo list for months, and no one seems to care, no one is assigned to it.
When it's brought up people are like "ooh yeah that's like really really bad, but what about [tiny useless feature than one user asked about]?we don't have the time to fix that!"<p>Hundreds of employees passwords for what's AFAIK our largest client, are stored in PLAINTEXT.(same story as the vulnerability, bottom of the todo list, no one cares)<p>Oh, and did I mention that any logged in user can call almost any API endpoints with almost zero verification that he's allowed to call them?<p>Those 3 issues are still there after months even though everybody is aware of them.<p>Would you just get the hell out without looking back? or keep trying to improve stuff even when it takes months to just get them to care enough to start maybe thinking about assigning a dev to a problem?<p>How is it at your current/past companies?<p>Thanks