3 ms·
It’s true. Look at the number of security bugs in Android, iOS, Windows, Linux, Oracle, DB2, SQL Server, PostGre, MySQL, Nginx, Apache, Cisco routers, Intel ch
by StressedDev 3y ago
It’s true. Look at the number of security bugs in Android, iOS, Windows, Linux, Oracle, DB2, SQL Server, PostGre, MySQL, Nginx, Apache, Cisco routers, Intel chips, AMD chips, etc.
The security bugs are not there because of incompetence or stupidity. They are there because security is really hard and it is even harder to get every software engineer to care about security.
If the best organizations in the industry make security mistakes, what makes you think the rest don’t either?
Reality is often unpleasant. It is better to acknowledge it than to pretend it does not exist.
- Kinrany 3y agoAgain, security is important for all of those products, but unlike all of them, Okta has exactly one job. Perfect security is impossible, but better than 50% odds of never getting critically compromised are reasonable to expect. If their security is not good enough, their value quickly becomes negative. Not only are they already a gigantic target and a single point of failure, but by being visibly bad at security they are standing in the spotlight with "hack me" on their back.
- guitarbill 3y agoWhat kind of argument is this? Sometimes, there are serious bugs in widely used products. So therefore shit vendors should get a pass when their 10 year old Apache instance gets owned? Because "security is hard, mkay"? No! It depends on the compromise. (If Okta was zero-dayed, IMO we'd have heard about it. Great way to shift blame.)
- esafak 3y agoYou can't say they all make mistakes and equate them. How frequent and severe are the incidents? How sophisticated does the attacker have to be to exploit these bugs? After reading all this I'm not inclined to consider Okta.