Now that beta is over for 5.0, I was just thinking about a project that I am working on that deals with user security. We had an incident were a developer innocently inserted a few lines of code while troubleshooting an exception so that it emailed the form data that a user entered to his email address. Well, like any large app, he forgot to remove the code and so he was getting data in his email after the release. Since this was not intended, we quickly had to release a new build without that code. No user was aware that it was doing that. I know from a developer standpoint it can be difficult to think of every possible scenario of how to fully secure an application, and one little tiny peice of code can make a "secure application" the mother of all insecure apps. So, since that time, once we are ready to release a new build, I like to use an recognized independent security expert to review the code, whom can certify that it is secure. This makes the users feel a lot better, as well as myself…
Since I am an end user and am "putting all my eggs in one basket" by putting my faith in Sticky Password's security, I was just curious if you guys have any type of formal independent security audit of Sticky Password code? As a developer, I always question that any application of this type is truly secure, and I know I always feel safer knowing that every measure has been taken to insure my data is safe...
TriadX1
