3 ms·
I feel like a checklist is just part of it. The truth is that a secure software development lifecycle needs to be taken seriously at every stage, and this costs
by artful-hacker 5y ago
I feel like a checklist is just part of it. The truth is that a secure software development lifecycle needs to be taken seriously at every stage, and this costs a lot of money. During prototyping and requirements gathering you need to be setting security requirements, vetting planned dependencies, and prototyping things like authentication and authorization. Each design should include threat modeling and threat mitigations. Implementation time should include mandatory code review, static analysis and secure code checklists. Testing needs to include manual penetration testing and dynamic scanning. Finally, maintenance is another area where things fall apart. Who is going to handle patching? Who will be accountable in 4 years when that version of Tomcat is EOL? None of these things are trivial, and people that have the skills to execute on them are rare. Getting a company fully willing to spend the money and time on them is even rarer. I had an old boss who aptly said once "Security is a black hole where money goes to die".
- lumost 5y ago> people that have the skills to execute on them are rare This is the limiting factor in secure coding. We need more efficient ways of scaling out the few teams doing top tier work, as it only takes a single bad code review to open a security hole. Teams should not need to implement their own authentication mechanism. Most companies should not need to implement their own mechanism. Authentication providers should explicitly and automatically verify that their clients have implemented auth correctly.