I would like to impress upon product managers that a code security review does not consist of me sitting down with the files in alphabetical order and reading each and every line exactly once in order and checking off whether it is or isn’t secure
Conversation
Notices
-
Embed this notice
abadidea (0xabad1dea@infosec.exchange)'s status on Tuesday, 10-Sep-2024 20:45:51 JST abadidea - GreenSkyOverMe (Monika) repeated this.
-
Embed this notice
abadidea (0xabad1dea@infosec.exchange)'s status on Tuesday, 10-Sep-2024 20:45:57 JST abadidea And if you’re wondering what it IS then, I would describe security review as more like mapping a cave system than reading a document.