Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends on the type of project. For something as big as nginx, unless you're a professional source code auditor with a lot of time, you pretty much need to rely on the "many eyeballs eyeballing the code." If big companies are using the product in production, you can bet many edge cases have been tested, bugs found and resolved.

For smaller stuff, what comes to mind is chrome extensions. Whenever I install some sketchy looking chrome extension like "user agent switcher" that requests permission to work on every URL, I always check the source code of the extension for any code that might exfiltrate data to external sources. Usually the source code is minimal and this only takes a few minutes. I do a quick scan for any code that is suspiciously obfuscated or seems to make an XHTTPRequest to a sketchy site, and if I see anything like that I "nope" right out of there.

It also comes down to what your threat model is and what you're trying to protect yourself from. If you know that, then you have an idea of what specifically to look for.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: