5 ms·
The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product
by binarymax 10y ago
The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches.
> Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make the first move, you’ll be waiting a while — but extend a hand to someone who expects a kick in the teeth and watch as you gain a new friend. Smile.
I really like this quote. A security engineer and a developer teaming up together as colleagues, are more likely to being taken seriously by stakeholders. Both teams working together have a much better chance of being given the time needed to make sure their software is stable and secure.
- pm90 10y agoI would like to add that while this advice would generally work, there are some really shady characters that one has to deal with sometimes. In that case, the other person might just keep taking advantage of your kindness. So, there does have to be a give and take: do a little bit, and hope that they do a little bit as well.
- jt2190 10y agoThis. In addition, there are people who are quite literally "dangerously wrong": They talk with great authority and can influence large numbers of people to follow them, even though what they advocate is non-productive. At best they can waste immense amounts of a community's time as they cause great debates among members. (Tabs versus spaces, for example.) At worst they gain actual authority, do great damage, and then leave the community to deal with the aftermath. (Cure your diabetes through positive thinking!) So while being "nice" and "empathetic" are excellent defaults when dealing with people, it's just as important to understand when ugly ideas need to be squashed and the undecided are urged to do what needs doing.
- vox_mollis 10y agomost developers would love to have the time to make sure their code is secure and well tested This is certainly true. But competitive pressures will always force quick hacks over software robustness. The only real solution is a sort of developers' guild -- whose membership includes over 90% of all worldwide professional developers -- wherein an oath is sworn to always include security robustness as a required feature during the software estimation cycle. Or perhaps an analogue to the Hippocratic oath. Which of course will never happen.
- dkopi 10y agoThe real solution in my opinion is educating people on security. not just developers, but also end users, sales people, and product managers. When users start choosing the robust and secure product over the quick and insecure product, sales will pick that up, product will follow, and programmers will treat security just like any other feature.
- vox_mollis 10y agoRespectfully disagree, here. Infosec has been trying the education path for decades, now. It's not working. Either something needs to change about the educational process, or acceptance that it's failed is warranted. I think fixing development will be more optimal than fixing users. There is no legitimate reason that OWASP top ten or lack of buffer bounds checking should still be in the wild in 2016, whereas users will always fall for scams, phishing or otherwise.
- maffydub 10y agoI think the challenge here is: if the users don't care, why should the CEO of your company? ...and if the CEO doesn't care, why is he going to want to pay developers to (as you say earlier) "always include security robustness as a required feature during the software estimation cycle"? So, unless the users _do_ care, the only way I can see this happening is if it costs no more to the CEO/users to do this than it costs not to... and that either means * all developers swearing your security "Hippocratic oath" (which, as you say, will never happen) * languages/tooling that mean that this becomes automatic (where there have been steps forward, but we're clearly not "there", and I doubt ever will be).
- sbov 10y agoUntil companies start being held liable for their software deficiencies there won't be a change. This is also why I find "Software Engineering" a joke. The equivalent of what passes for Software Engineering, in any other engineering field, would put people in prison.
- kazinator 10y agoThat's hardly the case. A lot of what passes for software engineering also passes for other engineering. What we actually see is a lot of apologizing, recalls and class-action suit settlements, and nobody actually seems to go to jail. Not all engineering is about bridges not collapsing; conversely, there is some software that is equally safety-critical and carefully developed. There is also "everyday engineering", like in consumer products. That's a category that fails miserably. Put simply, shit breaks. Past the one year warranty? Too bad!
- kazinator 10y ago> most developers would love to have the time to make sure their code is secure and well tested I'm suspect not. No matter how much time you have, it's more exciting to work on something new than going through testing. Time is not all equal. Even if you have an unlimited supply of time (everlasting life), you cannot somehow use a time block that occurs 1000 years from now, in order to displace the boredom you feel from what you're doing now. If anything, unlimited time will increase procrastination. "If this isn't debugged for another 500 years, that's okay; I will live long enough to see it debugged.". Thus, I suspect, most developers would actually love to have a vast army of other people with unlimited time to do the QA to make sure their code is secure and well-tested. :)