60 Percent of Developers Don

60 Percent of Developers Don't Trust the Security of their Applications

New research suggests that attacks based on open source code vulnerabilities will increase by 20 percent this year.

60 percent of developers aren’t confident in the security of their applications, and only 31 percent feel confident that their code doesn’t contain vulnerabilities, according to a new joint developer survey from NodeSource and Sqreen.

Enterprises are increasingly turning to open source tools like Node.js to save time and money while creating higher quality applications. According to Forrester, more than 76 percent of developers are currently using open source technology “at some level.”[1]

Yet, this enthusiastic adoption is not without risks. New research suggests that attacks based on open source code vulnerabilities will increase by 20 percent this year.[2]

While the developer community fully understands the risks of operating in the open internet and the complexities of building reliable, secure code, these same developers are not taking advantage of tools that can identify and mitigate threats. 

Surprisingly, fewer than a third of developers combine manual and automatic code reviews to search for flaws, or use automated tools to discover vulnerable modules. And a full 40 percent don’t check if there are known vulnerabilities in their third-party dependencies.

“Our survey results clearly demonstrate that security is a concern for developers — but not a priority,” said Joe McCann, CEO of NodeSource.

Only 35 percent of companies with fewer than 1,000 employees combine both code reviews and automated tools to check for vulnerabilities. Larger organizations make this more of a priority, with 62 percent saying they do both.

Prevention is a key piece of the security puzzle, but identification and remediation of attacks are also critical. Shockingly, the vast majority of the developers (79 percent) have poor to no insight into when their applications are under attack. And fewer than a quarter of Node.js developers use any form of real-time protection against attacks.

“Node is revolutionizing development for enterprises, but there is a lot of work to do to ensure the ecosystem remains secure,” said Jean-Baptiste Aviat, Co-Founder and CTO of Sqreen. “Developers have a wide array of security tools at their disposal that they are simply not using. We have more work to do evangelizing the importance of security tools for the health of the Node ecosystem.”

About the Author

Joe McCann is the Founder and CEO of NodeSource.

Featured

  • The Impact of Convergence Between IT and Physical Security

    For years, the worlds of physical security and information technology (IT) remained separate. While they shared common goals and interests, they often worked in silos. Read Now

  • Unlocking Trustworthy AI: Building Transparency in Security Governance

    In situations where AI supports important security tasks like leading investigations and detecting threats and anomalies, transparency is essential. When an incident occurs, investigators must trace the logic behind each automated response to confirm its validity or spot errors. Demanding interpretable AI turns opaque “black boxes” into accountable partners that enhance, rather than compromise, organizational defense. Read Now

  • Seeking Innovative Solutions

    Denial, Anger, Bargaining, Depression and Acceptance. You may recognize these terms as the “5 Phases” of a grieving process, but they could easily describe the phases one goes through before adopting any new or emerging innovation or technology, especially in a highly risk-averse industry like security. However, the desire for convenience in all aspects of modern life is finally beginning to turn the tide from old school hardware as the go-to towards more user-friendly, yet still secure, door solutions. Read Now

  • Where AI Meets Human Judgment

    Artificial intelligence is everywhere these days. It is driving business growth, shaping consumer experiences, and showing up in places most of us never imagined just a few years ago. Read Now

  • Report: Only 44 Percent of Organizations are Fully Equipped to Support Secure AI

    Delinea recently published new research on the impact of artificial intelligence in reshaping identity security. According to the report, “AI in Identity Security Demands a New Playbook,” only 44% of organizations say their security architecture is fully equipped to support secure AI, despite widespread confidence in their current capabilities. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.