40 karma · joined March 9, 2016
<shameless_plug>You may like https://pentesterlab.com/ if you are looking for a course</shameless_plug>
It's a problem with most learning resources, you get what you put it. Most people get out of these exercises one of these two things (or both):
#1 a real understanding of the issue (best case scenario) #2 awareness that encrypted/signed doesn't mean bulletproof.
Worst case scenario, I think these exercises help people with #2 and may get them to look a bit deeper when they are reviewing applications. It's not meant to be a crypto training (IANAC), the goal is to help people gain some awareness around crypto issues they may encounter during an assessment.
Long answer: it's a risk game, you may get away by showing that you have processes in place to manage this risk for open source projects: * internal backup of the source tree. * in-house skills to perform basic patching of the software if the development get discontinued. * alternative solution and roll-out plan in case the development of your current solution gets discontinued. * ...
Finally, risks can be accepted and someone ("the business") can sign-off on them. You don't have to remediate everything. It's just an awareness exercise for "the business".