7
5 Comments

Learnings from 5 years of tech startup code audits

This guy did 20-30 code security audits for startups, and has some solid learnings.

A few of my favorite takeaways:

  • Never deserialize untrusted data.
  • Acquisitions complicated security
  • There’s still a lot of MD5 in use out there, but it’s mostly false positive
submitted this link to Icon for group Developers
Developers
on June 1, 2022
  1. 2

    This was my favorite take away and what I think is such an important truth: KEEP IT SIMPLE.

    Basically, the startups he audited that are now doing the best had an almost brazenly ‘Keep It Simple’ approach to engineering. I'm not surprised, at all. He also makes a good point about moving to microservices too soon. I think he's right about that too. Thanks for the share.

    1. 1

      That great. To hear from you such detail information about their project and mission. Could you do audit of our https://apkreservoir.com/stick-cricket-premier-league-mod-apk/ and give us some good advices. So that we could move forward and make it one of the best business.

    2. 1

      Agreed! Everyone loves the idea of micro services but they are not the quick win people think they are. It's often easier to fix a bad monolith than bad microservices.

  2. 1

    Interesting lessons, thanks!

  3. 1

    Can't say I've ever gone through an acquisition, but his point about security complications is interesting.

Trending on Indie Hackers
AI runs 70% of my distribution. The exact stack. User Avatar 186 comments I'm a solo founder. It took me 9 months and at least 3 stack rewrites to ship my SaaS. User Avatar 147 comments I used $30,983 of AI tokens last month in Claude code on $200/mo plan User Avatar 60 comments my reddit post got 600K+ views. here's exactly what i did User Avatar 29 comments I turned someone’s tweet into an app idea and it has made ~$3000 so far in 4 months. User Avatar 28 comments We could see our AI bill, but not explain it — so I built AiKey User Avatar 25 comments