RE: RE: HiveSigner is INSECURE? - discussion and deep dive
You are viewing a single comment's thread from:

RE: HiveSigner is INSECURE? - discussion and deep dive

thedd(54)
Published in
HiveDevs
Words
86
Reading
1 min
Listen
Play
1y

Audited code is way more secure than closed source or unaudited code. BUT, reviewing a githib repo won't make the app secure! What stops the dev to alter the deployed version of the codebase and add some malicious parts?

The repo would look nice and shiny but a small change on the real server could be dangerous. So the full review should check the live webserver too. And it wouldn't be bulletproof either as you can swap dns record overnight or add changes after the audit.

@thedd: Audited code | Ecency