Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It depends on the situation, if something is broken in a live system and you can login and introspect the real thing this is awesome. Obviously there are trade offs and potentially you might break things further!


I'm used to introspecting live data with read only access. They used write access and were an accidental key stroke from deleting. Writing in prod should take permission escalation


Sometimes auditors won't even ok read-only access. I'd have loved RO access, but we hosted financial institutions etc.

Nice if you can get it.


With great power and all that...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: