|
|
|
|
|
by ransackdev
1032 days ago
|
|
How’s your vulnerability reporting process and how much experience do you have interpreting complicated pen tester bug reports about some buffer overflow zero day in your homebrew query string parser? Huge difference between working fine, and working right. The security implications of rolling your own, is why I say “you don’t want to…” Also, none of that code has anything to do with the product you’re actually trying to build. Imo it’s additional maintaining, tech debt, attack surface, and it’s a solved problem by a large community and has more knowledge from the security community baked in, and more eyes finding and plugging holes. |
|