3 ms·
Exactly this. Software development and security are basically the same thing. If you’re not writing secure software, and you don’t understand enough about net
by humbleMouse 6y ago
Exactly this. Software development and security are basically the same thing. If you’re not writing secure software, and you don’t understand enough about network layers to secure them, then you have a lot to learn just to get your knowledge up to par with a lot of devs/arch’s/“security people”
- _wldu 6y agoComputer Science is Security... Bruce Schneier agrees with your view: https://www.schneier.com/blog/archives/2016/06/computer_scienc.html https://www.schneier.com/blog/archives/2016/06/computer_scie...
- tidepod12 6y ago>Software development and security are basically the same thing. There is an entire universe worth of knowledge in the security space that has nothing to do with software development. I'd agree that 98% of the security world is "bullshit", but one of the reasons every company has such awful security is specifically because too many people think "software development" == "security", and this narrow mindedness means they end up failing to accomplish any of the security pillars that have nothing to do with software development. There is a lot of overlap specifically with secure development and software development, but saying "software development and security are basically the same thing" is naive. I like to compare it to a company's legal team: if you're going to court over a technical topic, you definitely want some people on your legal team that have software experience and you definitely want your general counsel to be technically educated, but that doesn't mean you're just going to take a software developer and make them your general counsel. You still need an actual lawyer, because there is an entire universe of law-related knowledge that you need that a software developer doesn't know.
- AmericanChopper 6y agoIn my experience, security roles have more to do with the practices of risk management than anything else. With security policy and compliance roles also requiring an element of jurisprudence.
- akiselev 6y agoExactly. Small stuff like having separate cloud accounts for different environments like prod and dev, enforcing MFA and password rotation, having separate ACL roles for different services with minimal permissions, basic antiphishing training, and so on are all low hanging fruit that few software engineers have the knowledge of and even fewer have the political capital to implement unless its handed down from the ops team. Instead defense in depth works best when the software engineers are treated as benign manifestations of hanlon's razor.
- andi999 6y agoI thought password rotation is considered outdated.
- bostik 6y agoIt is. The watershed publicity moment was in 2010, when the research paper came out.[0] It took another 6-7 years before the news percolated high enough in the political chain, and now both NIST and NCSC recommend against the outdated practices. And the infosec community had been arguing against the stupidity for what, 20+ years? Now, there is a place for rotation - when the so called password is in reality a shared secret. (Eg. the secrets in payment gateways.) Such things need to be rotated, because the basic assumption is that they will be compromised. No matter what you do, someone will copy-paste a long-lived secret to the wrong place at some point. 0: https://www.cl.cam.ac.uk/~rja14/shb10/angela2.pdf https://www.cl.cam.ac.uk/~rja14/shb10/angela2.pdf
- andi999 6y agoThanks. What I find the worst about 'must not be similar to past pw' is that you have to store the pw in plain text somewhere (or at least retrievable).
- BayesianDice 6y agoAn alternative to storing the pw in plain text is to ask the user to provide their current password at the same time as the new password. The password change routine can then check the current password is correct (which protects against the threat of an attacker coming across an unlocked terminal with a logged-in session and changing the password) and provides the current password against which the new password can be compared.