logoalt Hacker News

user34283today at 7:41 PM1 replyview on HN

On the other hand, I don’t need to review carefully every line of code in my thumbnail generator and associated UI.

My nonexistent backend isn’t going to be pwned if there is a bug in the thumbnail generation.

After the QA testing on my device, a quick scroll through of the code is enough.

Maybe prompt „are errors during thumbnail generation caught to prevent app crashes?“ if we‘re feeling extra cautious today.

And just like that it saved a day of work.


Replies

jaggederesttoday at 9:46 PM

> My nonexistent backend isn’t going to be pwned if there is a bug in the thumbnail generation.

Hmm. Historically image editing was one of the easier to exploit security holes in many systems. How do you feel about having unknown entities having shell inside your datacenter or vpc?

show 1 reply