Developers Failing to Use Secure Open Source Components

Discussion in 'other security issues & news' started by ronjor, Apr 12, 2018.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,080
    Location:
    Texas
  2. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    I think the over use of third party code libraries is a big part of the problem that no one wants to talk about.
    They are a prime target for those who want to subvert device security, they know if they can infiltrate an organisation or project that develops a code library and introduce a security flaw, it will potentially affect millions of users and most developers are not going to examine the code in code libraries, they just use the functionality they need for their project.

    I think there should be a website where all the individual classes that are bundled together in libraries are posted ready for developers to copy paste directly into their project. Especially crypto.
    Developers are far more likely to go over the code and spot bugs if they did that.
    Try and search for source code for any well known crypto it is hard to find.
    They always are saying dont roll your own crypto, use the code libraries, yeah sounds to me like advice to make sure the security flaws they introduce affect everyone.
     
    Last edited: Apr 12, 2018
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.