4 ms·
I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to sec
by proaralyst 9y ago
I have a feeling it's a subtly different problem: the people they've contracted to build this just don't understand security. They've evidently attempted to secure this, just in completely the wrong manner!
- jacquesm 9y agoHere's an interesting thought: what with the money there is to be made in security these days programmers that actually know everything there is to know about security will leave applications development. There is a good chance that the lure of security consultancy $ is resulting in a degradation of the quality of the applications.
- saral 9y agoApart from this time to market is also one of the reasons that such things get released to end customers.
- bkkssnn 9y agoAre you saying developers in general are subconsciously making low security products to raise the $ in security jobs globally, because they might some day switch career?
- klez 9y agoNo, they're saying that if the money is in security, developers that know about security will go to security, and whoever remains as a developer will not be good at security.
- sillysaurus3 9y agoThere's not nearly as much money in security as most security consultants would like you to believe. It's in their best interest for most people to believe there's a huge amount of money waiting for you if you switch to security. Unless you're someone with specialized experience (crypto), you as a pentester are worth around $100k/yr. That's excellent money, but it's not the massive margin that would drive people away from webdev.
- pwg 9y agoActually, the parent is correct. If the company providing the service were financially liable for these blunders, they would be careful to select contractors that are capable of meeting the security needs. As it is now, there is no financial incentive to select the "security aware" contractor, and the "non-aware" one is so much cheaper...
- toyg 9y agoOr rather they would hire more pentesters to make sure the sw they get is robust. On paper everyone can write "secure" apps...