4 ms·
I agree, it’s not usually a good use of time to reinvent the wheel, but what if there are unacceptable (e.g.) security risks with all the existing solutions? Th
by xmodinfinity 5y ago
I agree, it’s not usually a good use of time to reinvent the wheel, but what if there are unacceptable (e.g.) security risks with all the existing solutions? Then “just right” means “adequately addresses realistic security risks, where core fails to do so.” Developers correctly focus on building things, these aren’t often solid from a security perspective, and sometimes that matters. Abstracted, my point is that your point is correct in one domain, and there’s probably always another, peripheral domain where that’s not true: underlying assumptions mean whole ecosystems are flawed when used for a specific purpose: security, high availability, parallelism, etc
- eternityforest 5y agoI think developers almost always do address security, it's just that security is insanely hard and most aren't dedicating security specialists. CVEs are almost always patching in hours to days on mainstream software, it's rare to just leave doors open, the difference seems to just be in how much people tolerate things that might possibly have an unknown risk, just because they are big or use dependencies, or because they allow a user to do something that might be a bad idea in some contexts(Like have an unencrypted hard drive). If you need extreme security, or some other specialist requirement, you're total right, mainstream ecosystems can be unsuitable.