
Audio By Carbonatix
Lazy developers who copy solutions to tricky programming problems are creating apps that are vulnerable to attack, research suggests.A team of computer scientists looked at more than 72,000 chunks of code found on the Stack Overflow website.The site is popular with developers seeking advice on the best way to fix broken code.But researchers found many of the most copied snippets lacked basic checks that would stop common attacks.The dangerous code chunks often used obsolete functions, did little to check user responses and did not look for attempts to break the application, said the study.
Security risks
The researchers, also trawled through a website where many developers upload and share the code behind their apps and programmes.The most widely used insecure code blocks turned up in more than 2,800 separate projects on the Github website, they found.The research team, involving experts at Canadian and Iranian universities, focused on the C++ programming language, which is used in a huge variety of projects, from small programs to large distributed systems.The team informed those they found using the problematic code chunks on Github that they may have introduced security risks into their apps and programmes.The hard way
But only 13% of the developers contacted said they had fixed the code, the researchers said. A similar number declined to fix the bugs.Some 40% said the code was safe because users could not change it once an app was running."The people who are using Stack Overflow, they shouldn't trust it fully," said Prof Ashkan Sami, a computer scientist at Shiraz University in Iran who co-wrote the study."It's better for programmers to do it the hard way and learn secure coding," he told The Register tech news site.Prof Sami said the team had developed an extension for the Chrome browser that checks when code is copied from Stack Overflow and lets coders know if it is poorly written or insecure.DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
Kobina Atta-Bedi criticises government’s sole-sourced contracts, calls for reform
37 minutes -
Kwahu to become industrial powerhouse under new 24-Hour Economy – Goosie Tanoh
46 minutes -
Lawra MP donates transformer to Eremon SHTS to resolve power crisis
1 hour -
Lawra MP delivers medical equipment, commissions renovated nurses’ quarters
1 hour -
Livestream: Newsfile discusses galamsey taxes, sole-sourcing probes, Black Stars coach sacking and presidential dialogue
2 hours -
Ghana-Russia partnership supports mothers and children at Princess Marie Louise Hospital
2 hours -
Mother arrested for allegedly severing daughter’s toe in Juaboso
2 hours -
Iran and US race to find missing American crew member downed in fighter jet
4 hours -
Gomoa Easter Carnival: Samini, Ofori Amponsah and Kwabena Kwabena rock Day 2; Obrafour and Kwaw Kese set for Day 3 showdown
5 hours -
‘Comical joke’: Atta Akyea disputes ‘personal account’ claim in former NSB boss Adu-Boahene case
5 hours -
Kenpong intervenes as Afua Asantewaa, husband reconcile after public scrutiny
5 hours -
“Pay this, pay that, and the patient dies” – Former UGMC boss demands end to cash-and-carry in emergency care
5 hours -
Free Primary Healthcare: Gov’t floods clinics with 24,500 medical tools ahead of April 15 launch
6 hours -
Agyarko bolsters NPP chairmanship bid with Henry Quartey and Osei-Owusu as campaign leads
7 hours -
Sky-high spectacle as 2026 Kwahu Easter Paragliding Festival takes flight
7 hours
