5 ms·
I am not sure it is what is happening here, but a problem I have seen with internal QA and Security-focused teams is that they are incentivized to file bugs. Th
by markphip 3y ago
I am not sure it is what is happening here, but a problem I have seen with internal QA and Security-focused teams is that they are incentivized to file bugs. The number of bugs filed if their monthly/quarterly achievement, it has nothing to do with the quality of those bugs or how they improve the quality of security. Just "hey I found these 10 bugs that I labeled XXX severity".
I just imagine somewhere there are people updating their CV or something else with "filed XX CVE's" like it is some kind of accomplishment for them.
- baz00 3y agoHey they automated that where we are. I will spend several hours a week remediating impossible to exploit vectors to tick compliance boxes, while aircraft carrier sized holes in the front end go unpatched because they are hard to fix.
- rob74 3y agoLet me guess... you're using SonarQube too?
- baz00 3y agoNope I killed that. We have Wiz.
- beardedwizard 3y agoBut these are two very different things. Sonarqube is SAST (static analysis, reads the code you wrote) and SCA (composition analysis, reads the dependencies you declare). Wiz is just SCA. Sonarqube fps come largely from untuned SAST configurations flagging all manner of suspected CWEs (code weaknesses).
- baz00 3y agoCorrect. I don’t want either.
- beardedwizard 3y agoSo what exactly are you doing with wiz then?
- baz00 3y agoPay for it, employ monkeys to stare at it, raise lots of JIRA tickets and generally live in a state of misery.
- diarrhea 3y agoSome of our engineers talk about SonarCube this, dependabot that, Snyk this so much I am suspicious any actual work is done. Shackles made of red tape. Standstill is velocity. Freedom is slavery?
- baz00 3y agoYeah that. It seemed like a good idea but now we're enslaved by it.
- beardedwizard 3y agoSounds terrible. Doesn't have to be that way though. If it's not actionable and relevant, nobody should see it. If you really adopt this approach, the tool choice doesn't really matter except for the varying complexity of filtering to ensure only the good stuff gets bubbled up.
- n_ary 3y ago> Let me guess... you're using SonarQube too? You are an oracle. That thing is such a super pain in the a##, it has so many false positivies all over flagged that, I have to spend immense hours reviewing garbage failures on daily basis.
- dboreham 3y agoAsymmetric warfare here: it's easy for someone to run a security scanning tool and very difficult for someone to debunk the false positives it finds. But those two people don't work for the same boss.
- eddtests 3y agoThis is an issue with QA as a whole. It shouldn’t be some bug counting department - if they did their job well then they won’t find bugs at the end of the process (because bugs were found left, and bugs will still exist because exhaustive search isn’t possible). If you start quantifying the QA value on bugs found then worst case they don’t announce bugs on a month they’ve found their quota..