3 ms·
Building applications is a complex problem. If you want a secure system, then security details have to be carefully considered at every layer (DB, API, front-en
by _wldu 5y ago
Building applications is a complex problem. If you want a secure system, then security details have to be carefully considered at every layer (DB, API, front-end). Doing that requires expert security employees/consultants, time and money. On the other hand, profits are driven by new features, first to market and sales.
Companies can build insecure systems (that are profitable) much faster and much cheaper than they can build systems that are profitable and secure.
It has been my experience that security is seen as a necessary evil. It's not seen as a benefit or feature that customers want. Security employees/consultants are often seen as road-blocks or obstructionists. I think this is largely why technical security has been replaced by compliance. Just check the box mentality. When they get hacked they can say, "but we were compliant and we'll do better next time".
IMPO, that basic conflict explains why systems are repeatedly compromised and why companies nor customers really care about good technical security.
- jrumbut 5y agoThis is what I think when I hear about a company being attacked by someone inside their development/ops team or the latest 0day. Ideally there should be measures in place to mitigate these worst case scenarios but those are legitimately hard, expensive, and require commitment at all levels of the company. This wasn't that. The worst vulnerability was caused by a very basic mistake that was more at the level of fundamental competence than security expertise. If you're going to use GraphQL you need someone who knows about GraphQL. It's been out a while now, they aren't that hard to find.