(no subject)

Date: 2025-05-28 05:55 am (UTC)
voidampersand: (Default)
Where are the damn unit tests? If it's security code, it should have 100% code coverage, and there should be a white-paper explaining the domain, and there should be 100% domain coverage. Making sure the code works is not enough. You need to be sure there isn't any code that isn't tested. Any code that is not executed by tests is a potential bug. Maybe a potential exploit or even a back-door. It should be deleted with extreme prejudice.

Even if the code works perfectly, it is possible to have glaring security flaws. Like leaving clear-text passwords in memory. Failing to salt. Using a fast hash algorithm instead of a slow, secure one.

If it's custom encryption code, the risk factor goes up by a lot. Most new encryption algorithms are heavily scrutinized by experts before they are used in production. Which is a good thing, because most new encryption algorithms turn out to be crackable.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

Profile

little_details: An open book with a magnifying glass sitting on top of it, with the name Little Details written above. (Default)Little Details

June 2025

S M T W T F S
1234 567
891011121314
15161718192021
22232425262728
2930     

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 7th, 2025 03:27 pm
Powered by Dreamwidth Studios