829 karma · joined December 26, 2016
Some nice papers: https://arxiv.org/pdf/2002.07135 , https://arxiv.org/abs/2411.17343, https://doi.org/10.25300/MISQ/2025/49.1.075 or see https://arxiv.org/abs/2411.17343
There are many studies about this subject, but mind that complexity in code something different than 'complex' systems. You will need to dive into complexity science , but hard and 'soft' aspects should be taken into account when it comes to cyber security!
[1] https://nocomplexity.com/documents/codeaudit/complexitycheck...
As someone who loves Python, but lives in the EU I see too much emphasis on PyCON_US and US Python users and US firms. The Python world is far larger than US...
[1] See e.g. https://nocomplexity.com/documents/0complexity/principles.ht...
If you can not choose, just start with "Python Programming for Data Science". No barrier for starting, its cc-by and requires no account to read.
[1] Check: https://nocomplexity.com/documents/pythonbook/bookreferences...
A real concern should be Code-Level Backdoors in COTS software. Backdoors that even many resellers and paying customers are not aware off..
Conclusion: Type hints in Python libraries and frameworks primarily serve as API contracts rather than comprehensive descriptions of implementation details.
I come from C/C++, so for me using Python without type hints is the way forwards. But for some libraries it make sense. As long as type hints "do nothing"...but only for some tools.
I have serious doubt about this study. It's does not meet crucial reproducible research criteria. And most real-world Python-C Application are not FOSS and available on a public repository. But doing research on public repository is easy.
This paper focuses solely on public repositories. This is harmful and fuels the inaccurate perception that open-source software is inherently buggy, a view still promoted by commercial vendors and adopted by many managers worldwide.
"This change removes one source of potential confusion and misinterpretation, but does not mean download counts are an accurate measure of how many people use a package."
I think it is always better to make a clear distinguish between FOSS and OSS. Just to avoid these kind of issues in discussions again and again!
[1] https://nocomplexity.com/documents/pythonbook/bookreferences...
That's an option designed for users who are concerned about sending telemetry metadata to Tailscale.”
And imho a serious security architect should never ever allow telemetry on security products. Far too many risks.
After reading https://huggingface.co/blog/security-incident-july-2026:
I still have no clue what was detected or how bad this really is. There are a lot of words, but little to no concrete information. What is the current security architecture like? What is detected, and where? What goes undetected because logs aren't available? How many user datasets are at risk?
Remarking conclusion: "Alarmingly, we find thousands of apps leaking credentials, hundreds containing input injection vulnerabilities that allow arbitrary code execution, and tens harboring embedded backdoors—indicating active exploitation." AI use for creating applications seems insecurity by default...