No, you cannot trust third party code without reading it first

For more than a decade I have been thundering against a lot of the bad practices that have permeated the software development industry, one such practice is to blindly trust code when using third party libraries, frameworks or packages. For about the same amount of time I have listened to all the reasons why time is money and we need to build something quickly, and we haven't got the time to do security or X, Y and Z. But alas, now such companies are beginning to pay the price, a very costly and extremely damaging price! https://unixsheikh.com/articles/no-you-cannot-trust-third-party-code-without-reading-it-first.html

Creato 3y | 11 ago 2022, 16:21:23


Accedi per aggiungere un commento

Altri post in questo gruppo

What if one of your online friends dies unexpectedly?

A lot of people experience online friends "vanishing" without notice. A new nonprofit project tries to help prevent this issue. https://unixdigest.com/articles/what-if-one-of-your-online-friends-dies-

11 gen 2025, 00:50:03 | unixsheikh
There is only one reason why Microsoft Windows is the dominating operating system on the PC desktop

The Internet is filled with blog posts, articles on tech media, and videos on YouTube about why Linux is not the main operating system on the PC desktop. "5 reasons why", "10 reasons why", bla, bla, b

24 ago 2024, 03:10:06 | unixsheikh
How to install Signal Desktop on FreeBSD using the Linux Binary Compatibility

FreeBSD provides optional binary compatibility with Linux, commonly referred to as Linuxulator, allowing users to install and run unmodified Linux binaries without the need for virtualization or emula

22 ago 2024, 01:10:02 | unixsheikh
I passionately hate hype, especially the AI hype

I truly and passionately hate hype. From the fakeness of it to the sheer stupidity it represents, but perhaps most of all, because of the devastating consequence it often results in. https://unixdiges

21 ago 2024, 06:50:02 | unixsheikh
diff and patch

A mini tutorial in the usage of diff and patch. https://unixdigest.com/tutorials/diff-and-patch.html

5 mar 2024, 04:20:50 | unixsheikh
Who is listening on my ports

This is a mini tutorial in how to figure out what applications are listening on your ports on GNU/Linux, OpenBSD, and FreeBSD. https://unixdigest.com/tutorials/who-is-listening-on-my-ports.html

5 mar 2024, 04:20:49 | unixsheikh
Wrong default encoding on the Apache webserver

This is a mini tutorial in solving problems with the Apache webserver encoding specifications. https://unixdigest.com/tutorials/wrong-default-encoding-on-the-apache-webserver.html

5 mar 2024, 04:20:49 | unixsheikh