so Aarogya setu is now opensource. Everyone is talking about it but I want to vent out about some thing else. I am looking at the issue log and it simply is making me sick. thread to follow. cont.
I keep saying this if you raise such low level issues and create a lot of noise it helps no one. rather it creates a perception that sec is just making noise. Dont just report tool report why its wrong. again give details give specifics dont just run tool dump report. cont.
Important question that comes in mind why such a outrage from my side. The important part that people need to realize this is a out of the way step by govt we dont see that so frequently do we want to encourage it or discourage.cont
when the devs would have woken up to 81 issues 43 pull requests i can assume they would have been excited however when you see such low quality issues raised you endup doing what is called ignore or put it in cold bucket. no one likes to do that but you got to do it. cont.
my concern with low quality security issues is the same dont raise issues just coz a tool said something understand its context. provide details. its static analysis not saying it could be right or wrong but the context matters.
I am happy that govt took this step how community handles it going forward defines how govt continues to handle it going forward. only criticising coz you want to criticise is a wrong. if you feel its wrong tell them why and help them fix. contribute to better tomorrow.
You can follow @anantshri.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: