Stop being the product.
Become the owner.
Anyone else found Math.random() flagged in a security…
Anyone else found Math.random() flagged in a security audit? How did you handle the remediation? Security audit came back with a finding on credential generation. Math.random() in several services, flagged for NIST 800-63B non-compliance. The entropy requirements weren't being met and more importantly there was no documentation proving they were. We fixed the generation method but the audit documentation piece is what actually took the most time. Had to go back and document everything retroactively. Curious what others are doing here. Are you generating compliance documentation automatically as part of your pipeline or is this a manual process at your organization? #programming #js #technology #dev | earnings |
| 0 mlx total |
| $0
total |
| engagement |
| 1 views |
| 0 reactions |