7
5 Comments

Learnings from 5 years of tech startup code audits

This guy did 20-30 code security audits for startups, and has some solid learnings.

A few of my favorite takeaways:

  • Never deserialize untrusted data.
  • Acquisitions complicated security
  • There’s still a lot of MD5 in use out there, but it’s mostly false positive
submitted this link to Icon for group Developers
Developers
on June 1, 2022
  1. 2

    This was my favorite take away and what I think is such an important truth: KEEP IT SIMPLE.

    Basically, the startups he audited that are now doing the best had an almost brazenly ‘Keep It Simple’ approach to engineering. I'm not surprised, at all. He also makes a good point about moving to microservices too soon. I think he's right about that too. Thanks for the share.

    1. 1

      That great. To hear from you such detail information about their project and mission. Could you do audit of our https://apkreservoir.com/stick-cricket-premier-league-mod-apk/ and give us some good advices. So that we could move forward and make it one of the best business.

    2. 1

      Agreed! Everyone loves the idea of micro services but they are not the quick win people think they are. It's often easier to fix a bad monolith than bad microservices.

  2. 1

    Interesting lessons, thanks!

  3. 1

    Can't say I've ever gone through an acquisition, but his point about security complications is interesting.

Trending on Indie Hackers
$36K in 7 days: Why distribution beats product (early on) User Avatar 113 comments I've been reading 50 indie builder posts a day for the past month. Here's the pattern nobody talks about. User Avatar 105 comments Where is your revenue quietly disappearing? User Avatar 90 comments We made Android 10x faster. Now, we’re doing it for the Web. 🚀 User Avatar 71 comments Finally reached 100 users in just 12 days 🚀 User Avatar 65 comments a16z says "these startups don't exist yet - it's your time to build." I've been building one. User Avatar 57 comments