7 ms·
The survey polled 430 "mostly everyday programmers". Unfortunately, everyday programmers mostly know very little about security. Developers tend to think of se
by achou 9y ago
The survey polled 430 "mostly everyday programmers". Unfortunately, everyday programmers mostly know very little about security.
Developers tend to think of security as about avoiding coding mistakes, and that's reflected in their idea that security is about pen testing, code review, tools, etc. Any security professional will tell you that these are valuable but only a small part of the big picture. Take a look at Microsoft's SDLC for a wider view of what it takes to weave security into every aspect of software development[1]
Probably the single most valuable thing most development organizations could do to improve security of applications is to do threat modeling[2][3]. It's especially valuable in the early stages of application design, but it can be applied at any time. Threat modeling can increase awareness of how an application's security assumptions interact with its overall architecture. Thinking through your application's threat model systematically is the first step to prioritizing mitigations.
Unfortunately, this is voodoo to most developers even though it really should be an intrinsic part of designing application architecture. I've heard people say there's a mental block because the kind of thinking required for security is almost the opposite of that required to design and construct systems. I don't believe that though. I think it's mostly a matter of training and historical accident that security is even a separate discipline. It shouldn't be.
[1] https://www.microsoft.com/en-us/sdl/ https://www.microsoft.com/en-us/sdl/
[2] https://msdn.microsoft.com/en-us/library/ff648644.aspx https://msdn.microsoft.com/en-us/library/ff648644.aspx
[3] https://www.owasp.org/index.php/Application_Threat_Modeling https://www.owasp.org/index.php/Application_Threat_Modeling
- tomc1985 9y agoThere is a rich history of computer hacking that this community and others seems to have forsaken -- an entire generation of people who grew up with exactly that creative/destructive mindset. Unfortunately that ethos died when computer hacking became tantamount to terrorism in the government's eyes. The industry has done this to themselves, because we scream bloody murder every time there's a security breach.
- Retric 9y agoThere are deep historic and cultural reasons for this approach. Homes and businesses are generally not secure because the doors are locked, they are secure because the people around them don't try and break in or even check if the door is locked. In city's where that changes you see what looks like more security, but that has surprisingly little impact as it mostly convinces people to break in somewhere else. What changed in computing is the internet is the worlds largest 'city' by a huge margin and people can mostly automate checking to see not just if the door is locked but if the lock is of poor quality. Clearly in that situation laws are going to have limited value, but because they have been so successful in the past it's really hard to get out of that mindset. PS: Sure, there is crime, but compared to say 20,000 years ago the odds some kills you and takes your stuff next year is tiny.
- JumpCrisscross 9y ago> people can mostly automate checking to see not just if the door is locked but if the lock is of poor quality From across the world. Lack of proximity overturns the effectiveness of millennia of social norms.
- ozim 9y agoGood comparison with locks, because when you read lockpicking topics it looks the same. That pin tumbler locks are bad and whole industry for locks is bad because they should provide better options and throw away pin tumblers. Most of people are not getting robbed only having basic locks. Second is that actually thiefs are not picking locks but smashing doors or opening them with crowbar. I think it is a good idea to make hacking be viewed as heavy offense instead of fun and games. Of course you can do it on your own servers for fun but do not touch what is not yours.
- tomc1985 9y agoThat is effectively the law right now (at least in the US). But between a media circus of demonization (which frequently arises in cases like these), the government's demonstrated aggressiveness and zeal in pursuit of hacking charges (see Aaron Swartz), and public ignorance and fear, it is difficult to receive a truly fair trial.
- blanket_the_cat 9y agoI completely agree. It's strange to me that people are so scared of 'all of the hackers'. It's not like everyone with a black belt in karate runs around beating up everyone they see. Personally, everyone I know who has a deeper understanding of computer security, is so caught up in their curiosity, and getting 'that next trick' (more like skateboarders) that they don't even have a trace of the inclination, the time, or the threshold for the risk of prison time as it would interfere with their research, to plot and execute the type of stuff that people are so worried about.
- buzzybee 9y agoYou might like this talk on historical computer viruses and the shift from hobby to business in the 2000's. [0] [0] https://www.youtube.com/watch?v=yswPIwDFYDY https://www.youtube.com/watch?v=yswPIwDFYDY
- ScottBurson 9y agoIt's true that there are lots of white-hat hackers, but there are also lots of black-hat ones, many of them, I gather, associated with criminal organizations -- and as Retric points out, the Internet allows attacks to come from anywhere on the planet. I don't think it's responsible to suggest that people are unnecessarily worried about the problem. (Full disclosure: I work in the computer security industry.)
- ktRolster 9y agoUnfortunately, everyday programmers mostly know very little about security. If you really want security, it's something that every programmer should be thinking about, at least in the back of their mind, on every line of code they write.
- petra 9y agoMaybe it's actually should be the other way around ? Isn't it possible to build frameworks(using relatively popular/easy languages) for the most popular application classes(CRUD web apps, IOT MCU) that in many cases will isolate the developer from needing to think about security ? And if it's possible, And we already have a few such tools(like say scala lift, ARM mbed ) but somehow haven't yet became popular, why is that ?
- lbearl 9y agoMany of them already are, but they aren't "sexy". I personally do a lot of .Net, and MVC 5 has relatively good defaults if you just install and go. ASP.NET Core is even better in some regards (CSRF tokens are completely transparent now). I think a lot of the problem is that people want to use a lot of new tech which hasn't had time to develop security as a convenience feature, or they just flat out don't want to use a framework.
- ktRolster 9y agoIf you're writing queries, either through an ORM or by hand, you need to be thinking about what data will be returned to the user. If you're not thinking about it, you'll create a data leak in the best case.
- 2muchcoffeeman 9y agoI find most security 'training' to be really contrived. The examples are so trivial as to be useless and easily avoided in real life. I have had to do several 'security' training sessions. I understand it intellectually, but they don't instill a deep understanding.
- 9y ago
- flukus 9y agoYet one more thing developers have to worry about, as if the list wasn't long enough already. The developer world is still full of people creating sql injection attacks, I think you may be raising the bar to well beyond what is practical.
- mattkopecki 9y agoThis just means that you need to add that script kiddie scenario to your threat model and prioritize it accordingly.
- vacri 9y agoAt one place I worked, our commercial (wordpress) site got hacked and defaced by some Turkish outfit. The devs at our company reverted the site, and were joking about the hackers just being script kiddies. They didn't seem to understand my point of "... but we were hacked by those script kiddies, why are we laughing?"
- derefr 9y ago> I think it's mostly a matter of training and historical accident that security is even a separate discipline. Puts me in mind of the sort of systems you create working with the military: every line of code not only has to do its job, but has to be hardened against both electronic warfare (e.g. memory corruption from radiation from a maser) and cyberwarfare. It really does feel all of a piece when you get into that mindset.
- jacquesm 9y agoThe reason for this is really quite simple: every day programmers should not be concerned with security, that's systems level programming, not application level programming. But because the interfaces and protocols used for the creation of web services require remote access and hostile input suddenly you get an army of application programmers doing systems level work. So, to further your point: historically it was a separate level, the web has squashed systems programmers and applications programmers into the same layer of the sandwich.
- dasil003 9y agoIt's also squashed all the applications together in giant sandbox with a few strategically placed separators.
- collyw 9y agoCome on, you should know the basics and how to avoid them. SQL injection for example.
- jacquesm 9y agoYou are entirely missing the point. Of course you should know the basics, in fact, you should know everything otherwise what you build will be insecure. But traditionally the 'systems programmers' took care of those details for you and you could write your application in a wonderful trustworthy world. Until ~1992 hacking into a remote system was remarkably hard because there was far less software and that software had been vetted extensively before it was deployed by people who knew what they were doing. Now it's a free-for-all where everybody with $5 to spare can spin up a VPS and slap some insecure bunch of webstuff on it or cook it up themselves. That's a completely different situation.
- Chyzwar 9y agoIt is that in 90ties nobody predicted Internet. Most systems where build with assumption that network is trusted or no network. Secondly Moor Law consequences where visible after few years. Even MS did not predicted PC boom, everyone now have few computers. Both in terms of performance and availability of hardware we see it massive shift. It is extreme difficult to add security to system afterwards. In Last Kerberos vulnerability was fixed like last year (Kerberos is used from Windows 2000). Wordpress is still not secure... OpenSSL have something every year. > it was deployed by people who knew what they were doing. It is opposite. These people had no clue that systems they are building will be exposed to internet. Even if they did, it is all written in C on hardware that have very little protection (rowhammer).