惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
腾讯CDC
Y
Y Combinator Blog
L
LangChain Blog
B
Blog
U
Unit 42
P
Proofpoint News Feed
G
Google Developers Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
WordPress大学
WordPress大学
月光博客
月光博客
Vercel News
Vercel News
雷峰网
雷峰网
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗

JonahDevs

Building in Public: The ‘Back to It’ VS Code Extension – Part 1 Building in Public: The Time, the Silent Exploit: The Unseen Enemy in Every Codebase The Mindful Coder’s Workweek: 5 Themes to Enhance Your Craft and Satisfaction The Mindful Coder From Dirty Dishes to Clean Code: How Household Chores Mirror Programming Team Dynamics From Dirty Dishes to Clean Code: How Household Chores Mirror Programming Team Dynamics You’re Closer Than You Think: The Only 6 DNS Concepts You Really Need You The Wasabi Method: Shocking Your Way Out of Anxiety Attacks The Wasabi Method: Shocking Your Way Out of Anxiety Attacks Free Software: The New Nicotine? Big Tech’s Playbook Straight Out of Big Tobacco Free Software: The New Nicotine? Big Tech Your Gut is Smarter Than Your Spreadsheet: The Art of Software Estimation Your Gut is Smarter Than Your Spreadsheet: The Art of Software Estimation The Subtract Day: Why Less Code Can Lead to More Success The Subtract Day: Why Less Code Can Lead to More Success ESLint ESLint: Why We Actually Bother Understanding Nginx Part 1: The Power of Event-Driven Architecture Exercise Snacks: The Secret to All-Day Energy and Productivity How Important Clamping Is For Woodworking How to Fix Your Sleep Cycle Min/Maxing WordPress Hosting Min/Maxing My Internet Provider Everyone Uses Super Glue Wrong.
Time, the Silent Exploit: The Unseen Enemy in Every Codebase
Jonah · 2024-07-10 · via JonahDevs

You’ve got a bunch of gold sitting around because it’s holding its value great against inflation or because you are a dragon or something.

The first thing you will want to do is protect your valuable gold. The most obvious thing is to start off with a wall.

You do your research and build a wall or get someone to build one for you to the best standards of the time.

You now rest assured in the knowledge that your valuable plunder investment is safe.

People come from all over to marvel at your great wall.

It turns out that right under your nose, one of the people coming to look at the wall every day has been looking at it very closely and found a set of bricks they can use to climb up and over it.

Nothing has fundamentally changed in your wall’s construction, yet suddenly, with the knowledge of where to climb up, it your gold is effectively unguarded. Even worse, this person might sneak in and out many times, slowly taking gold bit by bit for days, weeks, or years without you noticing, or sharing this information with someone else that does the same.

In this case, the gold is your users’ data or elevated privileges to your system. The wall is any dependencies you are using or have written yourself.

In the end, our biggest enemy in cybersecurity isn’t just the hackers or the vulnerabilities – it’s time itself. Just as Andy Dufresne in Shawshank Redemption slowly chipped away at his cell wall over decades, patient attackers have all the time in the world to probe and exploit our code, as long as it remains public and unchanged.

The hard truth is this: if you want something you’ve released into the digital world to remain secure, you can never truly stop supporting or monitoring it. Like a vigilant guard constantly patrolling a prison’s walls, we must continually assess, update, and fortify our digital fortresses. Because in the realm of cybersecurity, there’s no such thing as “set it and forget it” – only eternal vigilance can keep our digital gold safe from those who would slowly, patiently tunnel their way in.