{"id":92062,"date":"2026-04-02T21:25:50","date_gmt":"2026-04-03T02:25:50","guid":{"rendered":"https:\/\/www.bricktowntom.com\/blog\/?p=92062"},"modified":"2026-04-02T21:25:50","modified_gmt":"2026-04-03T02:25:50","slug":"why-its-getting-harder-to-trust-the-software-we-use","status":"publish","type":"post","link":"https:\/\/www.bricktowntom.com\/blog\/04\/why-its-getting-harder-to-trust-the-software-we-use.html","title":{"rendered":"Why It\u2019s Getting Harder to Trust the Software We Use"},"content":{"rendered":"<p>Every piece of software we use requires some degree of trust. Whether it\u2019s a content management system, an office suite, or an operating system \u2013 each app we install is a small leap of faith.<\/p>\n<p>We have to trust, for example, that it\u2019s secure, respects our privacy, and works as expected. In other words: we need to believe that the developer has created an app with good intentions and that using it won\u2019t result in any intentional harm.<\/p>\n<p>That belief is tested daily. Security flaws, malicious attacks, and all manner of bugs pose huge challenges. And so much of an app\u2019s reputation depends on how the developer responds to these crises.<\/p>\n<p>But as we are seeing more frequently, trust isn\u2019t solely dependent on an app\u2019s primary developer. That responsibility also spreads to any third-party scripts and libraries their product utilizes.<\/p>\n<p>One prime example is the <a href=\"https:\/\/www.computerweekly.com\/news\/252512071\/Top-three-questions-about-the-Log4j-vulnerability\" target=\"_blank\" rel=\"noopener\">Log4j vulnerability<\/a>. A flaw in this popular logging library from Apache made it possible for an actor to arbitrarily run malicious code. Its effects could be devastating.<\/p>\n<p>As if this weren\u2019t bad enough, patching the vulnerability became incredibly <a href=\"https:\/\/security.googleblog.com\/2021\/12\/understanding-impact-of-apache-log4j.html\" target=\"_blank\" rel=\"noopener\">complex<\/a> due to how many other apps and service providers utilize Log4j. This meant that each app had to upgrade its copy of the library, then distribute the fix to users. The process has to repeat again and again.<\/p>\n<p>For web designers, this hits home on several levels. We put our trust into many apps (particularly open-source). And many have third-party dependencies. It puts us and our clients at risk.<\/p>\n<p>Let\u2019s take a deeper look at the issue and what web designers can do to stay safe.<\/p>\n<h2>Open-Source Software Is of Special Concern<\/h2>\n<p>The saga of Log4j has opened up a proverbial can of worms regarding open-source software in particular. In the United States, the White House held a <a href=\"https:\/\/www.zdnet.com\/article\/after-log4j-white-house-worries-about-the-next-big-open-source-flaw\/\" target=\"_blank\" rel=\"noopener\">meeting<\/a> with top tech firms regarding the security of widely-used foundational software that is maintained by volunteers.<\/p>\n<p>Popular examples include <a href=\"https:\/\/www.wordpress.org\" target=\"_blank\" rel=\"noopener\">WordPress<\/a>, <a href=\"https:\/\/nodejs.org\/\" target=\"_blank\" rel=\"noopener\">Node.js<\/a>, <a href=\"https:\/\/reactnative.dev\/\" target=\"_blank\" rel=\"noopener\">React Native<\/a>, and <a href=\"https:\/\/www.openssl.org\/\" target=\"_blank\" rel=\"noopener\">OpenSSL<\/a>. Beyond that, Google has <a href=\"https:\/\/github.com\/ossf\/criticality_score#public-data\" target=\"_blank\" rel=\"noopener\">published<\/a> a list of over 100,000 projects that are deemed \u201ccritical\u201d. They\u2019re relied on by everyone from governments, corporations, educational institutions \u2013 right down to personal and small business websites.<\/p>\n<p>This does not mean that any of the items on the list are inherently insecure. Rather, it\u2019s a measure of the potential impact a security flaw could have. As the OpenSSF Securing Critical Projects Working Group (WG) <a href=\"https:\/\/github.com\/ossf\/wg-securing-critical-projects\" target=\"_blank\" rel=\"noopener\">states<\/a>:<\/p>\n<blockquote>\n<p>\u201cFor our purposes, a critical OSS (open-source software) project is an OSS project that can have an especially large impact if it has a significant unintentional vulnerability, or if it is subverted in either its source repository or distribution package(s).\u201d<\/p>\n<\/blockquote>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/speckyboy.com\/wp-content\/uploads\/2022\/01\/trust-in-software-01.jpg?resize=900%2C400&#038;ssl=1\" alt=\"Computer code displayed on a screen.\" width=\"900\" height=\"400\" \/><\/p>\n<h2>Volunteers and Limited Resources<\/h2>\n<p>To state the obvious, security holes are not limited to open-source software. Big <a href=\"https:\/\/speckyboy.com\/proprietary-vs-open-source-cms\/\" target=\"_blank\" rel=\"noopener\">proprietary<\/a> projects from the likes of Apple, Microsoft, and other behemoths of tech also have their fair share.<\/p>\n<p>The difference is that these companies have the resources to ensure any issues, once discovered, are promptly fixed. Projects that rely on volunteers may not have such luxuries. Some may need to scramble to find someone knowledgeable who can take appropriate action in a timely manner.<\/p>\n<p>And if a project is no longer maintained? It places a huge target on anyone using that software \u2013 whether they know it or not.<\/p>\n<p>The beauty of these projects is that their volunteers are incredibly dedicated. We\u2019ve often <a href=\"https:\/\/speckyboy.com\/unsung-heroes-of-wordpress\/\" target=\"_blank\" rel=\"noopener\">saluted<\/a> those who work behind the scenes of WordPress, for example. The willingness of people to contribute their time and talents is a wonderful thing.<\/p>\n<p>But as Morten Rand-Hendriksen <a href=\"https:\/\/mor10.com\/open-source-considered-harmful\/\" target=\"_blank\" rel=\"noopener\">points out<\/a>, some major systemic issues need to be addressed:<\/p>\n<blockquote>\n<p>\u201cWe are acting as if these are still little hobby projects we\u2019re hacking away at in our parents basements. In reality, they are mission-critical, often at government levels, and what got us here is no longer sufficient to get us anywhere but chaos.\u201d<\/p>\n<\/blockquote>\n<p>It\u2019s admirable that a group of people, no matter how small or far-flung, can build an app that makes an impact on the world. But there are no assurances that the project will be sustainable over the long term. That can be problematic.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/i0.wp.com\/speckyboy.com\/wp-content\/uploads\/2022\/01\/trust-in-software-02.jpg?resize=900%2C400&#038;ssl=1\" alt=\"A laptop computer covered in stickers.\" width=\"900\" height=\"400\" \/><\/p>\n<h2>What Can Web Designers Do?<\/h2>\n<p>As web designers, we are in an awkward position. So much of what we do these days relies on open-source projects. And we reap the <a href=\"https:\/\/speckyboy.com\/web-designers-open-source\/\" target=\"_blank\" rel=\"noopener\">benefits<\/a> of them every day.<\/p>\n<p>The good news is that none of the issues outlined above means we have to abandon open source \u2013 nor should we. There is too much value in simply turning our backs on our favorite projects. If enough of us did so, that would likely make the situation worse.<\/p>\n<p>Instead, we should carefully consider the apps we are using. Gain an understanding of the project, who\u2019s involved, and the challenges they face. Look at its reputation within the industry and its longevity. Examine its changelog and see how often updates are released. Consider volunteering your time if you are able.<\/p>\n<p>It\u2019s also important to look at which third-party dependencies are associated with a project. This can be difficult to discern, but worth the effort.<\/p>\n<p>Then there\u2019s the role of service providers such as web hosts and APIs. They are additional links in this chain. Because, even if we\u2019re certain that an app we installed is safe, we also need to rely on these providers to maintain their systems as well. Monitor them as best you can and don\u2019t be afraid to ask questions.<\/p>\n<p>Placing blind trust in software is not a wise choice. And while it may feel nearly impossible to keep up with all of this, it\u2019s now a necessary part of the job.<\/p>\n<p>Truthfully, we won\u2019t be able to catch every issue before it becomes something bigger. But we can keep an ear to the ground and be proactive about the software we\u2019re using.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/speckyboy.com\/harder-to-trust-software\/\">Why It&#8217;s Getting Harder to Trust the Software We Use<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/speckyboy.com\">Speckyboy Design Magazine<\/a>.<\/p>\n<p>Source: Specky Boy<\/p>\n<p id=\"kc_opp\"><small>Republished by  <a href=\"http:\/\/www.blogtrafficexchange.com\/\">Blog Post Promoter<\/a><\/small><\/p>","protected":false},"excerpt":{"rendered":"<p>Every piece of software we use requires some degree of trust. Whether it\u2019s a content management system, an office suite, or an operating &hellip;<\/p>\n","protected":false},"author":1,"featured_media":92063,"comment_status":"false","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[128],"class_list":["post-92062","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-affiliate-marketing","tag-advantage"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/01\/trust-in-software-01.jpg?fit=900%2C400&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/p3k0YU-nWS","jetpack-related-posts":[{"id":93464,"url":"https:\/\/www.bricktowntom.com\/blog\/03\/woocommerce-wednesdays-creating-a-progressive-web-app-for-woocommerce.html","url_meta":{"origin":92062,"position":0},"title":"WooCommerce Wednesdays: Creating a progressive web app for WooCommerce","author":"admin","date":"March 27, 2026","format":false,"excerpt":"Today, more than half of all web traffic comes from mobile phones. As more and more shoppers turn to their smartphones to make online purchases, there is an increasing need for merchants to create differentiating mobile experiences. This has led native mobile apps becoming widely popular among ecommerce companies. They\u2026","rel":"","context":"In &quot;E-business &amp; E-marketing&quot;","block_context":{"text":"E-business &amp; E-marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/ebusiness-emarketing"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":92620,"url":"https:\/\/www.bricktowntom.com\/blog\/04\/should-market-share-matter-when-choosing-a-cms.html","url_meta":{"origin":92062,"position":1},"title":"Should Market Share Matter When Choosing a CMS?","author":"admin","date":"April 8, 2026","format":false,"excerpt":"All the world\u2019s a popularity contest. That holds true whether we\u2019re talking about movies, cars, or even content management systems (CMS). Everyone wants to come out on top. But, unlike those first two items, the number one entrant in the latter dwarfs all others. That would be WordPress, which happens\u2026","rel":"","context":"In &quot;Affiliate Marketing&quot;","block_context":{"text":"Affiliate Marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/affiliate-marketing"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/04\/cms-market-share-01.jpg?fit=900%2C400&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/04\/cms-market-share-01.jpg?fit=900%2C400&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/04\/cms-market-share-01.jpg?fit=900%2C400&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/04\/cms-market-share-01.jpg?fit=900%2C400&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":93061,"url":"https:\/\/www.bricktowntom.com\/blog\/04\/tips-for-handing-off-your-website-mockup-to-a-developer.html","url_meta":{"origin":92062,"position":2},"title":"Tips for Handing off Your Website Mockup to a Developer","author":"admin","date":"April 20, 2026","format":false,"excerpt":"If you\u2019re a web designer who works primarily on the front-end, there may be times when you need to hand your work off to a developer. Their job is to take your mockup and turn it into a working website. This is a big step in the process. To reach\u2026","rel":"","context":"In &quot;Affiliate Marketing&quot;","block_context":{"text":"Affiliate Marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/affiliate-marketing"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/06\/hand-over-your-mockup-01.jpg?fit=900%2C400&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/06\/hand-over-your-mockup-01.jpg?fit=900%2C400&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/06\/hand-over-your-mockup-01.jpg?fit=900%2C400&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/06\/hand-over-your-mockup-01.jpg?fit=900%2C400&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":93036,"url":"https:\/\/www.bricktowntom.com\/blog\/04\/useful-built-in-node-js-apis.html","url_meta":{"origin":92062,"position":3},"title":"Useful Built-in Node.js APIs","author":"admin","date":"April 15, 2026","format":false,"excerpt":"Learn about the most used and useful APIs built in to the standard Node.js runtime to save you time and improve your app's efficiency. Continue reading Useful Built-in Node.js APIs on SitePoint. Source: Site Point","rel":"","context":"In &quot;E-business &amp; E-marketing&quot;","block_context":{"text":"E-business &amp; E-marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/ebusiness-emarketing"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/05\/1654047218Useful-Node-APIs.jpg?fit=1200%2C600&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/05\/1654047218Useful-Node-APIs.jpg?fit=1200%2C600&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/05\/1654047218Useful-Node-APIs.jpg?fit=1200%2C600&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/05\/1654047218Useful-Node-APIs.jpg?fit=1200%2C600&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.bricktowntom.com\/blog\/wp-content\/uploads\/2022\/05\/1654047218Useful-Node-APIs.jpg?fit=1200%2C600&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":92945,"url":"https:\/\/www.bricktowntom.com\/blog\/03\/weekly-news-for-designers-%e2%84%96-644.html","url_meta":{"origin":92062,"position":4},"title":"Weekly News for Designers \u2116 644","author":"admin","date":"March 25, 2026","format":false,"excerpt":"Optimize Images App \u2013 This online app features 9 image optimization tools, along with both free and premium options. Variable Fonts Support in Figma \u2013 Get the inside scoop on Figma\u2019s support for variable fonts. 10 Free Portfolio & Lookbook Templates for Adobe InDesign \u2013 Quickly build an amazing portfolio\u2026","rel":"","context":"In &quot;Affiliate Marketing&quot;","block_context":{"text":"Affiliate Marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/affiliate-marketing"},"img":{"alt_text":"Envato Elements","src":"https:\/\/i0.wp.com\/speckyboy.com\/wp-content\/uploads\/2019\/08\/envato-elements-weekly-news.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]},{"id":92668,"url":"https:\/\/www.bricktowntom.com\/blog\/04\/weekly-news-for-designers-%e2%84%96-639.html","url_meta":{"origin":92062,"position":5},"title":"Weekly News for Designers \u2116 639","author":"admin","date":"April 6, 2026","format":false,"excerpt":"10 Tools & Resources for Building a WordPress Staging Site \u2013 Test software updates and experiment with your own staging environment. WeekToDo \u2013 Check out this privacy-focused free planner app for Windows, macOS, Linux, and your browser. 33 JavaScript Concepts Every Developer Should Know \u2013 A handy reference of concepts\u2026","rel":"","context":"In &quot;Affiliate Marketing&quot;","block_context":{"text":"Affiliate Marketing","link":"https:\/\/www.bricktowntom.com\/blog\/category\/affiliate-marketing"},"img":{"alt_text":"Envato Elements","src":"https:\/\/i0.wp.com\/speckyboy.com\/wp-content\/uploads\/2019\/08\/envato-elements-weekly-news.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/posts\/92062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/comments?post=92062"}],"version-history":[{"count":2,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/posts\/92062\/revisions"}],"predecessor-version":[{"id":94449,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/posts\/92062\/revisions\/94449"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/media\/92063"}],"wp:attachment":[{"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/media?parent=92062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/categories?post=92062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bricktowntom.com\/blog\/wp-json\/wp\/v2\/tags?post=92062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}