Changelog Master Feed cover image

Lessons from 5 years of startup code audits (Changelog Interviews #494)

Changelog Master Feed

00:00

Is Stripe the Only Person Who Can Hit That en Point?

Web hook implementations by relatively large third parties that i won't name don't allow for authentication. A lot of times it's pretty bad, especially if you're dealing with money or subscriptions. Almost every j w t library out there didn't do some sort of check when there was no algo. Don't roll your own crypto stuff rather than rolling their own. Your last number made it 16, we've made it five more in the past few days. We still highly recommend everyone use open source stuff even though the vons had vons on them.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app