4 ms·
I would bet that a developer knew of the security issues, but was vetoed by Product.
by ryanmccullagh 2y ago
I would bet that a developer knew of the security issues, but was vetoed by Product.
- deleted 2y ago[deleted]
- neilv 2y agoThe usual case for software development the last decade is developers who don't fully understand what they're doing, and are mostly focused on resume-driven-development (RDD) and looking good in Agile sprint standups. Noteworthy exceptions: FAANG promotion bid orientation, and VC growth startup alignment towards shipping something to look like growth towards exit. In a small minority of cases, you have developers who know what they are doing, and are thinking rigorously. The norm isn't big-meanie Product making (forthright, courageous, photogenic) developers ship negligent security vulnerabilities, against developers' protests. Developers are at least as much responsible as Product.
- ryanmccullagh 2y agoNot getting time to do security because we need to ship v1 is a decision called by Product
- neilv 2y agoIf you know of a developer who would've done responsible security, but was pushed to ship instead, against their protest, I'd be happy to hear that.
- ryanmccullagh 2y agoIn my experience, Product is always the first one to suggest cutting corners.
- neilv 2y agoPart of the job of Product is triage on all sorts of things. But I don't think there's hardly any developers who would've done something securely but didn't because Product said no.