Audio By Carbonatix
Lazy developers who copy solutions to tricky programming problems are creating apps that are vulnerable to attack, research suggests.
A team of computer scientists looked at more than 72,000 chunks of code found on the Stack Overflow website.
The site is popular with developers seeking advice on the best way to fix broken code.
But researchers found many of the most copied snippets lacked basic checks that would stop common attacks.
The dangerous code chunks often used obsolete functions, did little to check user responses and did not look for attempts to break the application, said the study.
Security risks
The researchers, also trawled through a website where many developers upload and share the code behind their apps and programmes. The most widely used insecure code blocks turned up in more than 2,800 separate projects on the Github website, they found. The research team, involving experts at Canadian and Iranian universities, focused on the C++ programming language, which is used in a huge variety of projects, from small programs to large distributed systems. The team informed those they found using the problematic code chunks on Github that they may have introduced security risks into their apps and programmes.The hard way
But only 13% of the developers contacted said they had fixed the code, the researchers said. A similar number declined to fix the bugs. Some 40% said the code was safe because users could not change it once an app was running. "The people who are using Stack Overflow, they shouldn't trust it fully," said Prof Ashkan Sami, a computer scientist at Shiraz University in Iran who co-wrote the study. "It's better for programmers to do it the hard way and learn secure coding,"Â he told The Register tech news site. Prof Sami said the team had developed an extension for the Chrome browser that checks when code is copied from Stack Overflow and lets coders know if it is poorly written or insecure.DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
Arla Foods marks World Milk Day with nutrition drive for 42,000 students in Central Region
12 minutes -
BoG’s reforms on community banking aims to build well-capitalised banks – ARB Apex Bank MD
15 minutes -
Government to establish health posts at all land borders to strengthen Ebola preparedness
18 minutes -
Tetegu residents blame authorities over dredging failure at Densu River amid Weija Dam spillage
18 minutes -
Don’t just query KATH – invest in emergency infrastructure, GMA tells government
24 minutes -
GMA clarifies KATH A&E congestion, says no emergency patients were turned away
29 minutes -
Ghana and Jamaica strengthen bilateral relations with new cooperation agreements at third PJCC session
39 minutes -
Adenta building collapse: Victim died trying to save her children—Sister recounts
45 minutes -
Owner of collapsed Adenta building to be arrested for ignoring stop-work order – La Nkwantanan MCE
48 minutes -
Accra floods: We have done things the “wrong way” for over 40 years – GhIE President
52 minutes -
Ukraine accused of killing four in occupied Crimea
54 minutes -
2026 WAFCON: Asamoah Gyan inspires Black Queens with training visit
55 minutes -
US House delivers rebuke to Trump as it votes to halt Iran war
1 hour -
Accra Floods: Water retention systems are compromised – GhIE President
1 hour -
PFAG backs rice import quota policy, demands urgent action over worsening rice glut
1 hour