|
|
|
|
|
by jamessocol
5084 days ago
|
|
As long as you're using the tools provided, you're doing your due diligence. The framework provides a lot, and the ecosystem usually provides the rest. The "last mile" is just making sure your code is using all those tools correctly. |
|
And yet that example may only be the last item in a threat tree, which may have a zero-day vulnerability at its root.
Relying on tools or, in fact, any code you've not written yourself makes your system vulnerable. If you understand how an attacker might compromise a system (ref. STRIDE) you can mitigate.