4 ms·
Also in security and 100% tired of the code slingers who get annoyed by security reviews Here on HN it’s been derided as “company just checking a box for compl
by Inf0s3c 3y ago
Also in security and 100% tired of the code slingers who get annoyed by security reviews
Here on HN it’s been derided as “company just checking a box for compliance but adds no functionality. It slows us down when we want to disrupt!” - developer of yet another todo list or photo editor app…
Buffer overflows and the like are one thing. Notions from this blog that certain normal files won’t be well reviewed is a bad smell in software. Innocuous files should be just as rigorously reviewed as it’s all part of the state of the machine
“This is how it’s always worked” is terrible justification
Startup script kiddies git pulling the internet, and single maintainers open source projects aren’t cutting it; if it’s that important to the whole those in charge of the whole need to make sure it’s properly vetted.
I’m an EE first; this really just makes me want to see more software flashed into hardware.