425
you are viewing a single comment's thread
view the rest of the comments
[-] mac@infosec.pub 147 points 6 months ago

I thought it was poking fun at the tutorial saying instead of learning to code, import a library from someone who knows how to code.

[-] lowleveldata@programming.dev 41 points 6 months ago

That's what libraries are for. I'm no security expert and the sensible thing to do is using a library instead of taking a class.

[-] bort@sopuli.xyz 25 points 6 months ago* (last edited 6 months ago)

I’m no security expert and the sensible thing to do is using a library instead of taking a class.

Counterpoint: "not knowing your libraries" + "blind trust in the maintainer" will give you stuff like this: https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in

(the thread itself is worth a read. But also very impressive is the list of big players who fell for exactly this mentality)

[-] Gabu@lemmy.ml 3 points 6 months ago

Impressive and unsurprising. As soon as you start getting complex libraries with multiple dependencies it becomes nearly impossible to review everything. At one time I had an interest in contributing to some AI libraries, but they're a mess as soon as you go looking for points of improvement.

load more comments (3 replies)
load more comments (3 replies)
load more comments (6 replies)
this post was submitted on 03 Apr 2024
425 points (89.1% liked)

Programmer Humor

32281 readers
969 users here now

Post funny things about programming here! (Or just rant about your favourite programming language.)

Rules:

founded 5 years ago
MODERATORS