4 ms·
The real solution in my opinion is educating people on security. not just developers, but also end users, sales people, and product managers. When users start
by dkopi 10y ago
The real solution in my opinion is educating people on security. not just developers, but also end users, sales people, and product managers.
When users start choosing the robust and secure product over the quick and insecure product, sales will pick that up, product will follow, and programmers will treat security just like any other feature.
- vox_mollis 10y agoRespectfully disagree, here. Infosec has been trying the education path for decades, now. It's not working. Either something needs to change about the educational process, or acceptance that it's failed is warranted. I think fixing development will be more optimal than fixing users. There is no legitimate reason that OWASP top ten or lack of buffer bounds checking should still be in the wild in 2016, whereas users will always fall for scams, phishing or otherwise.
- maffydub 10y agoI think the challenge here is: if the users don't care, why should the CEO of your company? ...and if the CEO doesn't care, why is he going to want to pay developers to (as you say earlier) "always include security robustness as a required feature during the software estimation cycle"? So, unless the users _do_ care, the only way I can see this happening is if it costs no more to the CEO/users to do this than it costs not to... and that either means * all developers swearing your security "Hippocratic oath" (which, as you say, will never happen) * languages/tooling that mean that this becomes automatic (where there have been steps forward, but we're clearly not "there", and I doubt ever will be).
- blue_dinner 10y agoThe problem is two-fold. The average users doesn't care about security and probably never will. Many developers like to hack software together. To make it secure requires discipline and more time and knowledge when developing it. Most businesses don't really care about this. They just want it finished fast. The only way it will change is if the government starts fining companies for software that has a crazy amount of bugs or requiring developers to be certified. I honestly don't think many developers even have the ability to write software without the obvious bugs we see popping up today. For sure we would see less companies outsourcing to countries like India.