3 ms·
And of course you regularly check back for bugs and security issues, right?
by ldng 4y ago
And of course you regularly check back for bugs and security issues, right?
- snovv_crash 4y agoUsually the security issues come from the wrapper code that tries to hammer the square peg of an algorithm into the round hole of the abstraction they provide. Dropping the wrapper code is the safest thing you can do.
- raesene9 4y agoI used to be a web app security tester. I loved it when I got an app that didn't use a framework for development because I knew I'd get some security issues for sure. In the context of web applications, frameworks mean that your devs don't have to be experts in SQL Injection, XSS, SSRF, Session management etc etc etc. My experience over several hundred tests was that without a framework there weren't many apps that could get that right first time. If they were lucky the pentesters found the issues, if they were unlucky, it was attackers.
- snovv_crash 4y agoA library could work here too, to turn off the footguns and provide safe tooling. No need for the library to also intercept all of the DOM callbacks for you as well.