3 ms·
Wow, how can this amount of files be justified? And how did this breached exactly happen?
by yawaworht1978 5y ago
Wow, how can this amount of files be justified?
And how did this breached exactly happen?
- samtho 5y ago> Wow, how can this amount of files be justified? File count is not a good metric of complexity nor is an indicator of the quality of an application. There is a good chance a lot of that are packages that have been packaged up into the extension. Lastpass itself is not a super trivial application, either.
- hetspookjee 5y agoI think for a security application you want to reduce your exposure as much as possible, and one way to do so is reducing the amount of dependencies in your application. I think a high dependency count is orthonogal to that.
- feoren 5y agoNitpick: "orthogonal" would mean "independent of"; that is, a high dependency count has no effect on exposure. I think you might have meant "antithetical", meaning "in opposition to".
- deleted 5y ago[deleted]
- 101011 5y agoTo be fair, orthogonal just means something that’s at a right angle to another line. I’ve heard people refer to something that is opposite, or an antonym to parallel (or in sync) as orthogonal.
- albedoa 5y agoHere it means "perpendicular". A high dependency count is perpendicular to the goal of reducing exposure as much as possible.
- Strilanc 5y agoSeems like a pretty good metric of complexity to me, particularly when it comes to a security audit. Having a lot of packages packaged up in the extension corresponds to having a lot of source code you have to vet, lest it be an avenue of attack.
- tgsovlerkhgsel 5y ago"total of 25MB of javascript" is a good metric of the complexity of the application's code, and correspondingly the difficulty of auditing it (I'd say 25 MB of JS code make it infeasible).
- VWWHFSfQ 5y ago25MB of plaintext lines of javascript code is absolutely an indication of the complexity
- kerneloftruth 5y agoFile count and general "bloat" is an indicator of the quality of the engineering in the product. Especially for a security product _minimalism_ should be evident -- nobody with good security sense would want or allow anything not truly necessary to the product's functionality to be included. There's a lot of room between "super trivial" and "needlessly complex" -- it shouldn't be either. Trusting a cloud-based third party with my passwords is a non-starter for me.
- tyingq 5y agoI posted the GP, with the sizes, etc. I think they do have a somewhat hard problem to solve though. They probably also want to minimize remote calls so that the extension is functional offline, is more secure, etc. Which would drive the size up, especially with localized errors, etc.