|
|
|
|
|
by tremon
3492 days ago
|
|
You use a library. On what basis did you choose that library? Did robustness of the software come in to your evaluation? Did you request a sample from the supplier, and performed stress testing on it? Did you check for certifications/audits of the code you were including in your project? If that library is found to contain a vulnerability that allows your site to be used in a DDoS, where do the "consequences for failure" lie? With you, unless you have a contract with your supplier stating otherwise. |
|
And even if, you implement rigorous audit of code, that means you can't update, because you have to go through the same audit rigamarole, each time a bug is found. By the time you audit your software, a new vulnerability will probably be discovered.
Not to mention this essentially makes open sources software nonviable.