3 ms·
Just guessing as an outsider, but... it's a big, conservative car company trying to do software development. Reasons could include: - Too much red tape/risk as
by jamesrr39 3y ago
Just guessing as an outsider, but... it's a big, conservative car company trying to do software development. Reasons could include:
- Too much red tape/risk assessments/effort/time required to set up a credential store
- Devs working there may not know/understand the importance of it, and may not be up-to-date with modern software development practices.
- Assumption that Github repo will always be private, correctly configured, never leaked.
- Assumption that employee computers with code checked out will always be full disk encrypted and source code never read by a malicious program/transmitted somewhere else.
If you work in a company that makes software for a living, it's worth bearing in mind you are probably nearer the forefront of modern best practices and there are many companies in other industries that do some software as part of, but not the main part of the product, and these do not necessarily focus on software development and therefore may be "as hot" with best practices, to put it mildly.
- mass_and_energy 3y agoI mean, I think it's fair to say that given they're developing their "Drive Pilot" level 2 SAE software, at least some of this code involves life-or-death systems. For that reason alone I'd expect a higher level of security awareness, so seeing how unhygienic their repos are from a sec perspective is a bit unsettling.
- kdmccormick 3y agoAgreed it is unsettling. For what it's worth, there's some peace of mind in that this software is probably tested much more thoroughly than the average piece of Web software or whatever. Version control / security best practices / clean code may be too abstract for these old companies, but testing isn't. You'd hope.