That Salesforce OAuth hole wasn't a surprise — it was tech debt

Jessie Grenfell
Jessie Grenfell
That Salesforce OAuth hole wasn't a surprise — it was tech debt

Baloney. That OAuth vulnerability was known at Salesforce, of that I am certain.

But CTOs / COOs- when you e-signed with Salesforce did you know that, until about a month ago, anyone with a Salesforce login could install a third-party app that used their credentials to access company data? Possibly (hopefully) against your internal policy.

This was known, just like so much of the tech debt baked into Salesforce. Some of it dates back decades. Some came from acquisitions that were half-integrated, then abandoned as the next shiny thing got resources: Pardot, Vlocity, FSC, etc. Even internally developed features have been left to age awkwardly.

Short-term gains over long-term quality — the disciples of Milton Friedman call it natural law. I call it greed-driven contempt for your customers.

Jessie Grenfell

Jessie Grenfell

Jessie has spent 20+ years architecting and delivering software for organizations where complexity is the norm — financial services, insurance, nonprofits, and regulated industries where getting it wrong isn't an option. She specializes in the hard problems: unique operational workflows, cross-system integrations, and the kind of compliance requirements (HIPAA, CCPA, SOC 2) that most developers treat as someone else's job.

At Codality, she leads every principal engagement from discovery through delivery — because she's seen what happens when that thread gets cut.