4 ms·
s/Encryption/Security Roll-your-own cryptography is definitely the worst of it, but even developers that use strong crypto libraries end up misusing them quite
by devmor 2y ago
s/Encryption/Security
Roll-your-own cryptography is definitely the worst of it, but even developers that use strong crypto libraries end up misusing them quite often.
I have worked on a lot of custom made web software, and I could count the number of in-house authentication or authorization systems that didn't have glaring issues on one hand.
After nearly 12 years of working in this field, I would consider myself extremely knowledgeable in web security and I still don't think I'd be comfortable writing a lot of these types of systems for production use without an outside analyst to double check my work. Unless you're a domain expert in security, you probably shouldn't either.