3 ms·
I would only expect that if the people rewriting everything were good programmers and said they were rewriting it to be secure. Most rewrites are done for non-
by deialtrous 8y ago
I would only expect that if the people rewriting everything were good programmers and said they were rewriting it to be secure. Most rewrites are done for non-security reasons are don't improve security.
- mannykannot 8y agoProgrammers should give appropriate attention to security regardless of whether they are doing either original work or a rewrite, and in the latter case, regardless of the reasons for the rewrite. I would not regard those who do otherwise as good programmers. Clearly, a DHCPv6 client within Linux' system administration suite is a case where security is an issue of the first magnitude.
- deialtrous 8y agoProgrammers should do a lot of things that most of them do not do. The statement was "I would expect..." and I replied that it doesn't make sense to expect those things because the vast majority of programmers don't know or care about security at all. We still see the same trivial SQL injections being written again and again on today's web, often by 20+ year programming "veterans".