logoalt Hacker News

aurareturntoday at 7:00 PM1 replyview on HN

Releasing the server code isn't always ideal. There's likely a ton of secrets, hardcoding, and exploits.


Replies

tethatoday at 7:25 PM

Regarding 1 and 2, my pity is mild if this requirement forced companies to follow principles of secure software development, configuration and deployment. Injecting stuff from deployment config is not hard.

3 is valid and can be tricky, as it would depend on when in the software lifecycle the release would be mandatory. If it's in a wind-down or bankruptcy situation, it would be tricky. Though that discussion is similar to the responsible disclosure discussion, isn't it? Exploiters usually already know them.

show 1 reply