Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Absolutely, but my way of going about this would be to first show _why_ something is a best practice, rather than forcing people to take it at face value.


The problem is that people are allowed to take the easy route, they will never write secure code.

Writing secure code is always harder than not, and developers love to take shortcuts.

For example, many of the IO functions like gets() are no longer valid in C11 exactly because how unsafe they are.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: