Join Nostr
2026-08-13 08:51:50 UTC
in reply to

Dr. Hax on Nostr: Sure. I wouldn't say a quiet record is proof that the code is free of ...

Sure. I wouldn't say a quiet record is proof that the code is free of vulnerabilities. It could be that nobody looked, or that the vendor is good at strong arming people into keeping quiet.

However, I would say that a record of lots of high severity vulnerabilities is evidence of poor code and/or design. If AI can actually produce that, it's more transparency, and good projects can really shine. Currently, projects that don't cram a ton of features are punished by the market. I'd be happy to see the market atart putting more value on reliability, security, and long term support.

Aa I said, when there's a lack of evidence, we just go on dependencies, complexity, and code smells. It's not nothing, but it's not proof either.