logoalt Hacker News

Akronymus • today at 1:00 PM • 3 replies • view on HN

Also, your own library, at this point, is much less of an attack vector than some dependency from a package manager


Replies

dotancohen • today at 1:19 PM

From maintaining dozens of projects over decades: yes and no.

Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.

➕ show 4 replies
ipsod • today at 1:08 PM

Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.

I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.

➕ show 1 reply
v3ss0n • today at 1:50 PM

LLMs will easily exploit it these days.