No, you cannot trust third party code without reading it first

For more than a decade I have been thundering against a lot of the bad practices that have permeated the software development industry, one such practice is to blindly trust code when using third party libraries, frameworks or packages. For about the same amount of time I have listened to all the reasons why time is money and we need to build something quickly, and we haven't got the time to do security or X, Y and Z. But alas, now such companies are beginning to pay the price, a very costly and extremely damaging price! https://unixsheikh.com/articles/no-you-cannot-trust-third-party-code-without-reading-it-first.html

Creată 3y | 11 aug. 2022, 16:21:23


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

What if one of your online friends dies unexpectedly?

A lot of people experience online friends "vanishing" without notice. A new nonprofit project tries to help prevent this issue. https://unixdigest.com/articles/what-if-one-of-your-online-friends-dies-

11 ian. 2025, 00:50:03 | unixsheikh
There is only one reason why Microsoft Windows is the dominating operating system on the PC desktop

The Internet is filled with blog posts, articles on tech media, and videos on YouTube about why Linux is not the main operating system on the PC desktop. "5 reasons why", "10 reasons why", bla, bla, b

24 aug. 2024, 03:10:06 | unixsheikh
How to install Signal Desktop on FreeBSD using the Linux Binary Compatibility

FreeBSD provides optional binary compatibility with Linux, commonly referred to as Linuxulator, allowing users to install and run unmodified Linux binaries without the need for virtualization or emula

22 aug. 2024, 01:10:02 | unixsheikh
I passionately hate hype, especially the AI hype

I truly and passionately hate hype. From the fakeness of it to the sheer stupidity it represents, but perhaps most of all, because of the devastating consequence it often results in. https://unixdiges

21 aug. 2024, 06:50:02 | unixsheikh
diff and patch

A mini tutorial in the usage of diff and patch. https://unixdigest.com/tutorials/diff-and-patch.html

5 mar. 2024, 04:20:50 | unixsheikh
Who is listening on my ports

This is a mini tutorial in how to figure out what applications are listening on your ports on GNU/Linux, OpenBSD, and FreeBSD. https://unixdigest.com/tutorials/who-is-listening-on-my-ports.html

5 mar. 2024, 04:20:49 | unixsheikh