5 ms·
It’s time to fix software security. And it’s gonna be hard. First, there is no unbreakable software. Second, software is written by average people vs above-the
by csbartus 5y ago
It’s time to fix software security. And it’s gonna be hard.
First, there is no unbreakable software. Second, software is written by average people vs above-the-average people who are hacking it. Mission impossible.
- only_as_i_fall 5y agoIs there evidence that the average hacker is smarter than the average developer? I would expect the opposite to be true because legitimate work seems more profitable/stable, but also I'd imagine the difference is t that high either way
- dennisnedry 5y agoOf course not, this is just the parent poster's opinion. The truth of the matter is that there exceptional individuals who decide to get into software development and software security. The problem with software is that often companies don't invest into securing their software, and that has to be a priority. Perhaps having the SEC force fines for not securing mission critical software is the first step?
- datameta 5y agoI think the incentives are lopsided. The developer does not personally bear the blow of their company's data breach (unless they're dedicated cybersec personnel) whereas the hacker reaps all the reward of getting access.
- deleted 5y ago[deleted]
- IncRnd 5y agoThe parent never used the word "smarter". By definition, the average developer is developing applications, but the non-average developer is doing something else, possibly hacking. Hacking is not the average activity (the way that word is used today). With regards to skill sets, I have repeatedly found that people who engage in hacking range from skill sets of "knowing how to use a hacking kit" to "uber developer with security knowledge". There is a wide range of skills and knowledge. However, it is practically an entry requirement for someone in the security space to view software differently than most programmers. That is defined as non-average.
- fragmede 5y agoThey didn't say smarter but they did say above-the-average which implies better (as opposed to worse), rather than it being a different skill set. That is to say, I know exceptional "hackers" who can't code their way out of a pair bag, or build any sort of GUI. Similarly, I know some really good programmers who don't intimately understand how computers work a tenth as well as hackers do. There are genuinely smart people in both camps, but they're different skill sets.
- csbartus 5y agoI remember after finishing our CS studies we were taken by the Army to take a day long test. We were warned better fail the test unless we are willing to be enrolled. However this might be an isolated case. In turn, I guess a security professional is more scarce than an average developer. The question is if all security professionals are hired to strenghten systems, or some of them to break it.
- fragmede 5y agoYes, large engagements frequently include a "red team" who's job it is to try and break into the system.
- csours 5y agoI used to think this way, it can be really dangerous to assume level of intelligence from background information. More to the point, hackers can be very motivated to break things in a way that the average developer is not motivated to secure them.
- datavirtue 5y agoYou hit it. Cracking a system that has mountains of attack vectors is interesting, fun, and potentially profitable. There is so much to probe and try. Flip it around and look at the priorities of software developers Ina corporate setting. Most of them are so sick of dealing with security hoops and theatre it's the last thing they want to think about.
- datameta 5y agoMaybe the cost equation becomes more evident to companies: dedicated above-average internal* cybersec staff < (SEC fines + outcry when breach goes public) * external seems like a different can of worms. perhaps someone in cybersec can refute/expand
- datavirtue 5y agoThere is no one to hire. Brainless monkeys are getting paid deep into six figures to watch dashboards and do security scans and check off boxes.
- aledalgrande 5y agoMore than avg vs above avg I would say it's building a cards castle vs making a cards castle fall. The latter is way easier.
- datameta 5y agoAnd as a card castle toppler, you only have to find the most unstable one in a group. Perhaps to many companies it seems like a revenue sink to implement proper security. It Probably Won't Happen To Us™ and so forth. Okay. Maybe it seems like a more concrete return on spend if a company were to frame the goal as trying to be at least as fit as the average of the herd.
- gitanovic 5y agoSorry, this is not true. The real issue is that software has many bugs as the sum of all contributes to it, and all it takes is finding one. What I mean is that it takes just one sloppy developer to introduce a bug, and that's all you need. Making unbreakable software is a much harder task than breaking it. It's not about who's smarter, it's about what's easier.
- csbartus 5y agoI still believe it’s about who does what. Code written by an average developer is breakable by a better skilled developer. Vice versa is not true.
- orf 5y agoThat’s not how any of this works. At all. Not even slightly. Like, what? “Thank god, I only hire developers with a skill level of 78 so it will take a developer of skill level 79 or above to even have a chance at finding a bug here, and we all know skill level 79 developers are rare so I’m secure!” This isn’t an RPG, life is full of unquantifiable things and differing conflicting incentives. If anything, the domains in which exceptionally skilled developers often work and the tools they use make bugs more common. It doesn’t take a Linus Trovalds to find bugs in Linus Trovalds’s code.
- gitanovic 5y agoI strongly disagree... also superstar make mistakes, and cannot know every single quirk. In particular when you have languages (like C++) with tons of "features" that enable very weird side effects in very weird situations. By the way the worst clusterfuck I ever saw was caused by a very talented programmer that implemented a very complex object store on disk... the thing was brittle at best, and it failed in very spectacular ways. Very entertaining to debug
- datavirtue 5y agoSloppy or extremely busy and/or over-worked. Throw a few desk side jobs at me while I'm maxed out with story points and I can practically feel the bugs flowing into the code. I'll get it all done but...someone is going to pay later.
- adrianmonk 5y agoThere are really two problems that could go under the name of "fixing software security": (1) How do you improve the state of the art, so that, if a company is serious about security, they can succeed? (2) How do you fix the way companies are run so that they actually even try to take security seriously? Both are big contributors to the overall problem. I do think there is room for improvement in #1, so it's something we should be looking at. But we could get a lot of mileage out of #2 even if there were no way to move the needle on #1.