5 ms·
I'm sure the executives take issues like this incredibly seriously. None of this stuff is insidious in nature, it's just what happens when people bypass process
by collinf 9y ago
I'm sure the executives take issues like this incredibly seriously. None of this stuff is insidious in nature, it's just what happens when people bypass processes.
Engineer doesn't take the time for proper password management -> Password gets left in source -> Other engineer who does code review misses password -> this continues for several iterations -> product gets released.
Unfortunately this definitely happens more often than you would want to think.
- paulie_a 9y ago> I'm sure the executives take issues like this incredibly seriously Considering Cisco's history of security issues they clearly don't take it seriously and it is unlikely that will change.
- Jach 9y agoCouldn't the same have been said about Microsoft say pre-Vista? Of course taking security seriously doesn't magically make you have competent staff and eliminate embarrassing vulns, Windows has still had its share post-Vista. A lot of "taking security seriously" can just turn into security theater cheerleading and focusing too much on certain processes (especially response over prevention[0]) without ever doing effective threat modeling. [0] You fixed a reported admin-attacking-admin XSS bug within the SLA, good job! You're also letting admins upload binary blobs you then parse, has anyone run a fuzzer on this to help uncover any potential code execution bugs? Does anyone even know what a fuzzer is? No? Carry on... Until something gets reported.
- user5994461 9y agoI don't think that's a fair comparison. The internet didn't exist when windows 2000 and XP were done.
- paulie_a 9y agoSarcasm, drunk or high?
- user5994461 9y agoNone of these. In the decade around the 2000's, we went from almost zero computer in the developed world, to virtually every household having one and they're all permanently connected through a high speed network. That's a new universe of unplanned threats and attack vectors. None of this was anticipated when operating systems were designed, a few years before release.