3 ms·
> The problem with 'defense in depth' No, that's a problem with bad engineering. That a process requires skills most people attempting it don't have isn't a pr
by _jal 3y ago
> The problem with 'defense in depth'
No, that's a problem with bad engineering. That a process requires skills most people attempting it don't have isn't a problem with the process, it just means that it is hard and relatively new.
One thing I see all the time that demonstrates this incompetence is talking about something being more or less "secure" without reference to a threat model. You simply can't make reasonable tradeoffs without thinking this through, and yet nobody wants to do the exercise.
In fairness, this is not just an engineering fault. I've seen one case where a legal department freaked out when they heard about a risk analysis project in pursuit of a formal threat model - they vehemently objected to anyone producing documents about such things that could potentially surface in some discovery fight.
- horsawlarway 3y ago> One thing I see all the time that demonstrates this incompetence is talking about something being more or less "secure" without reference to a threat model. You simply can't make reasonable tradeoffs without thinking this through, and yet nobody wants to do the exercise. Hey - I completely 100% agree. Believe it or not, I did quite a stint in software security before becoming this jaded (5+ years fulltime work at a security focused product sold primarily to large fortune 100 companies [banks - it was all banks]). I think my problem is that for any difficult challenge... there is an answer that is simple, obvious, and incorrect. My opinion is that the incorrect answers I see most are the two extremes: I don't care about security (BAD!). I only care about security (WORSE!!!!). The first will eventually lead to compromised accounts/data and that can kill a company. The second will lead to products no one wants to use, which WILL kill a company. Neither is a good spot to be. You want to find an appropriate compromise in the middle: Secure enough. ---- Side note - no one truly does the threat assessments based on threat model because no one in industry likes the answers. For small and inconsequential threats - you are already secure enough. For nation states - there is likely no solution that is workable if the thing is on the internet. It's like trying to buy a secure door for your house: For most folks walking down the street, the current door is fine. When the Gov shows up with tanks - there is no door you can buy to solve the problem.
- deleted 3y ago[deleted]