3 ms·
I'm curious what your thoughts are on potential solutions to writing 'secure' (enough to resist non APTs, assuming the human does not fall for phishing, just ha
by Multicomp 3y ago
I'm curious what your thoughts are on potential solutions to writing 'secure' (enough to resist non APTs, assuming the human does not fall for phishing, just hardware/software vulns) software as an industry?
Slower releases? Formal verification everywhere? Demanding more than 3 days notice and vague requirements before we start implementing features? Unionization/licensure so devs can pushback when bosses of various stripes want to cut corners like they have gotten to their entire careers?
It is clear that the industry of popular commercial computing devices at large does not have the incentives to write 'secure' code and hardware as defined above.
What would it take to make the default state be secure instead of insecure?
My attempt at fixing incentives leads me over to UNIX and C which was a massive paradigm shift from the mainframes before and arguably is the foundation for modern computing at large today.
Trying to kill our old 80s insecure-unless-you-really-work-at-it UNIX & C-dynasty might be a good step but seems almost impossibly painful for us to do.
Like how medical best practices in some areas can only move forward one death of an old guard doctor at a time. We all (me included) are used to this von neumann architecture on one of several popular ISAs and doing imperative code pretending to be a PDP-7, plus or minus lots of abstraction, depending on where we go from embedded to Blazor WASM web programming.
Let's say someone does do that, a new OS from first principles, new programming language(s), an entire stack built on, IDK, ARM or x86 ISA on up. VC money demands they lock out making the device general purpose computing. Few would buy it because of their sunk cost investments in the cloud / SAP / activedirectory corporate networks / X gen enterprise offerings of the past that this would not be as easily integrated with.
Yikes. What will it take to make us as an industry write 'secure enough' software by default?