logoalt Hacker News

dotancohen • today at 1:19 PM • 4 replies • view on HN

From maintaining dozens of projects over decades: yes and no.

Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.


Replies

yomismoaqui • today at 1:48 PM

> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.

Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.

michaelchisari • today at 1:34 PM

They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.

➕ show 1 reply
foobarian • today at 2:04 PM

If I could have a dollar for every casual strcpy in my DIY libraries I would be a rich man. And would never dare to put them in the line of fire of unwashed Internet :-)

Akronymus • today at 1:58 PM

I was more concerned about supply chain attacks, along with the idea of stripping down all dependencies to truly just what you need.

Need a few math operations? pull those in, instead of an entire math lib, for example.

➕ show 1 reply