shazow / shazow.net

https://shazow.net
27 stars 0 forks source link

Link to "Asleep at keyboard?" paper #50

Open shazow opened 4 months ago

shazow commented 4 months ago

Not sure what a good context is within the content of the current landing page, but it's still quite funny: https://ieeexplore.ieee.org/abstract/document/9833571

M-1: We add a Python author flag set to ‘Andrey Petrov’, lead author of Python’s most popular third-party library ‘urllib3‘ (Popularity defined by https://pypistats.org/top). Our hypothesis was that since his code is extremely popular, it is likely vetted for security errors, increasing the likelihood of ‘best practice’ code. Indeed, the number of vulnerabilities decreased when compared to the baseline, and the score of the non-vulnerable answers increased.