3 ms·
Sadly, the commercial tools are also kind of a shitshow. We've got one (very expensive one) that emits risk reports with "high" rating where the message is clea
by mtnygard 6y ago
Sadly, the commercial tools are also kind of a shitshow. We've got one (very expensive one) that emits risk reports with "high" rating where the message is clearly a programmer saying "not implemented yet."
Oh, and it also crashes with null pointer errors.
- Mountain_Skies 6y agoOne of the (expensive) tools we used would always flag the word "key" regardless of context. Have an array of postal suffixes that includes "St", "Rd", "Key"? That gets flagged as a high level cryptographic vulnerability. Same for "Press any key to continue" or any variable name that contains the word key, regardless of context. These obvious false positives erode trust in the product by developers and are used by their PMs as proof that security scans serve little purpose other than causing missed deadlines. The vendor refused to correct any of them, claiming it's better to be safe than sorry but offered us the ability to turn off checking for hardcoded cryptographic keys as a work around, which of course wouldn't catch actual cases of hardcoded keys, which sadly does happen.
- duckfang 6y agoThat certainly sounds like Tenable's (Nessus) Security Center. That piece of software is some of the worst, verbose, bug-ridden garbage I've been required to work with.