DEV Community

Discussion on: Is open-sourcing server-side code a security threat?

 
_hs_ profile image
HS

It takes renaming API endpoints not to get a warrent to be able to comapre 2 codes. That's all it takes.

On security side I put my money where my mouth is. I would never expose my backend code. I don't see code for AWS stuff nor Azure nor Google search engine and so on.
But if anyone wants to go ahead. I'm not buying "obscurity" statment as good enough to say go expose your code.

Thread Thread
 
lexlohr profile image
Alex Lohr

You're not fooling anyone if the data structure and the output is still the same. Also, I'm not saying that you should by all means expose your code, just that the "security" argument is leading into dangerous thinking about security.