Pupil mental health monitor promises app rewrite after hardcoded login creds discovered

Sloppy coding and deployments are run of the mill now, despite there being an abundance of security checklists for such common requirements as how to 'harden' response headers for Varnish or Cloudflare caching or how to set up SSL certificates. Lots of companies (TCS, Accenture to name just 2) often fail dismally at checking to see if a deployment from Test/UAT to production has removed development credentials etc.

This is usually coupled with a reluctance to pay the extortionate fees required for full penetration testing.

