3 ms·
There's no silver bullet. Pledge on a complex application that does too many things [requests too many permissions] doesn't help much. IMO complexity and chur
by foxfluff 5y ago
There's no silver bullet. Pledge on a complex application that does too many things [requests too many permissions] doesn't help much.
IMO complexity and churn remain the biggest problems but people are not willing to engage it. There's always at least one legitimate use case for some faddy trendy new feature, always a reason for more complexity, fuck anyone who doesn't want it. And so you get a massive body of constantly changing code that auditors can't keep on top of.
What would it be like if your chat app was max 3000 lines of code and received no more than a handful of small patches per year since 2008? You could audit that in an evening or two and be reasonably confident in its security, and you could also be reasonably confident that it hasn't grown a bunch of new vulns in the next three releases, and you could quickly audit it again to be sure.
Alas, practically nobody takes you seriously if you advocate for simplicity. Usually it's the opposite; I tend to get attacked if I suggest that a program/system might be too complex.