Secure Coding mailing list archives

Root Canal Treatment vs Source Code Review


From: ljknews at mac.com (ljknews)
Date: Tue, 01 Jul 2008 10:22:21 -0400

At 10:43 PM -0400 6/30/08, Mary and Glenn Everhart wrote:

There is another reason I have seen quite often: you can't readily ask 
the designer of
the code what it does when he is dead, or when he has left the company 
(esp. if he works for a competitor).

When I participated (as author) in formal inspection there were
as many defects found (and fixed) in the comments as in the code.
And most people think my comments are better than average.

I have "left the company" but still have some access to see
what defects they have found since.
-- 
Larry Kilgallen


Current thread: