NYCPHP Meetup

NYPHP.org

[nycphp-talk] Injection Attack, any ideas?

Elliotte Harold elharo at metalab.unc.edu
Tue Nov 13 18:39:03 EST 2007


David Krings wrote:

> I disagree, you can take shortcuts, such as not documenting code and 
> omitting anything other than the "how it is supposed to be used" path. 
> One might argue that this would not constitute project completion, but 
> when time and money are scarce for a software project the QA and doc 
> team get cut and 'cheaper' developrs get hired to do the job. Typical 
> behaviour in companies where shareholder value (short term gain) is 
> valued more than product quality (long term gain).
> 

I don't believe in shortcuts to quality. I believe short iteration 
cycles that accomplish a minimum of functionality well rather than a lot 
of things poorly. No one knows what they want till they see it anyway. 
Deliver the simplest thing that can possibly work; then add to it as 
time permits and desire dictates.  YAGNI is a guiding principle.

-- 
Elliotte Rusty Harold  elharo at metalab.unc.edu
Java I/O 2nd Edition Just Published!
http://www.cafeaulait.org/books/javaio2/
http://www.amazon.com/exec/obidos/ISBN=0596527500/ref=nosim/cafeaulaitA/



More information about the talk mailing list