12 ms·
If it was true that trust is enough to market software, there would be much more investment in application security by the long tail of startups, consultancies,
by CiPHPerCoder 7y ago
If it was true that trust is enough to market software, there would be much more investment in application security by the long tail of startups, consultancies, and webdev "shops".
What I've found over the years is that most people who sell software think of security as a value-add. At best, it's something to bill enterprise customers for. At worst, it's a cost center that will only be invested in if a big paying customer asks for it explicitly, and not a moment sooner. [1]
For background: I spent years pushing the PHP ecosystem forward in cryptography and security. I published a lot of open source libraries [2], cleaned up a lot of StackOverflow answers [3], and had a lot of discussions with small and medium businesses about security improvements that ultimately went nowhere because they couldn't find budget for security.
I don't believe it's fair to say that trust is "at the core" of software marketing if so many successful software companies can get by without investing in making their products trustworthy. After all, deception can obviate trust in this context.
(I do believe that software ought to be more trustworthy, and society should reward companies that act with integrity. But at the end of the day, that's not my call to make.)
[1]: https://sso.tax https://sso.tax
[2]: https://github.com/paragonie https://github.com/paragonie
[3]: https://paragonie.com/blog/2018/01/our-ambitious-plan-make-insecure-php-software-thing-past https://paragonie.com/blog/2018/01/our-ambitious-plan-make-i...
- reaperducer 7y agoI don't believe it's fair to say that trust is "at the core" of software marketing if so many successful software companies can get by without investing in making their products trustworthy. After all, deception can obviate trust in this context. What you're seeing is companies that ignore security and trust at their own peril. There are plenty of them, and the vast majority of startups, that don't realize how important trust and security is to large customers. Then they wonder why they can't get their foot in the door at certain companies. The place I work for runs every software purchase through a security committee. For that reason, we tend to go with the big brands that take security seriously. But it's not exclusively big brands. I worked on a particular project that needed a particular type of software. None of the big brands had anything similar. I put together a list of five options and sent it over to the people who actually get to make the decisions. All five options were small developers (fewer than 50 employees). Only two of those five bothered to respond to the initial inquiries from our security people. Of the two that responded, only one provided answers to the follow-up questions. Guess which one got a ~$250K purchase order the next month.
- deleted 7y ago[deleted]