3 ms·
I’ve tried (and abandoned) a similar question suite for Security SWEs. Giving people sample code riddled with security flaws and asking them to explain what was
by strstr 7y ago
I’ve tried (and abandoned) a similar question suite for Security SWEs. Giving people sample code riddled with security flaws and asking them to explain what was wrong.
I found it difficult in the security domain since so much of it is context dependent (what’s the interface? Is this code in the kernel? Are you concerned about speculative side channels?). I also found it difficult to calibrate.
There’s probably a good question space in there if I were to spend time testing the questions more, but there are enough other questions in the neighborhood that I’ve moved on.
- irjustin 7y agoI agree, the analog isn't a good fit. With EE there's a floor of knowledge that basic "bad schematics" can build off of.