4 ms·
Then you get to write 10x the vulnerabilities yourself and not have nearly the same chance of any of them getting disclosed to you!
by hyperhopper 2y ago
Then you get to write 10x the vulnerabilities yourself and not have nearly the same chance of any of them getting disclosed to you!
- ChrisMarshallNY 2y agoThat argument doesn't seem to be aging well. I'd say that good [emphasis on "good"] coders can write very secure code. There's fundamental stuff, like encryption algos, that should be sourced from common (well-known and trusted) sources, but when we load in 100K of JS, so we can animate a disclosure triangle, I think it might not be a bad time to consider learning to do that, ourselves.
- vikramkr 2y agoIt's impossible to tell how that argument is aging since we don't have the counterfactual.
- sandwitches 2y agoSo if you can't trust your developers to manage dependencies, and you can't trust them to write dependencies... why have you hired them at all? Seriously, what do they actually do? Hire people who can program, it isn't hard.