3 ms·
Sure but what does "rewarding security", as the author suggests, in a way that is genuinely meaningful look like? The direct metric would a low number of secur
by GrumpyYoungMan 2y ago
Sure but what does "rewarding security", as the author suggests, in a way that is genuinely meaningful look like? The direct metric would a low number of security holes or bugs in the product but then you run straight into the problem that many holes/bugs are not found until much, much later, if ever. Perhaps code review failed to notice it, perhaps QA didn't cover that case, perhaps security scanning tools missed it, perhaps no black or white hat hacker ever bothered to try to break it, etc. Without a meaningful metric, what will likely happen is that people get rewarded for some kind of security theater.
- nocsi 2y agoThen go the opposite route. South Korea fines companies thousands of dollars every day a vulnerability isn't fixed. Security is one of those areas where negative reinforcement works better than positive reinforcement.
- felixhammerl 2y ago"thousands of dollars every day" does not a negative reinforcement make. That us not even a rounding error for even mid sized companies.
- paulryanrogers 2y agoThen use 1% of revenue or 2K per day, whichever is greater.
- Manouchehri 2y agoSo after 4 months, the company would lose more than their entire revenue?
- paulryanrogers 2y agoYeap, should deter building vulnerability riddled solutions.
- BobbyTables2 2y agoWhy not? A $20k car can do far more than $200k in damage. We don’t limit liability to the price of the vehicle.
- Manouchehri 2y agoThe equivalent would be a $20k Ford resulting in a $1,762,000k fine.
- Manouchehri 2y agoMind providing a source? (Tried to Google it but didn’t find any relevant info.) I can think of multiple situations where a vendor from SK has left things unpatched for months, and sometimes years..
- GrumpyYoungMan 2y agoSure, I'd be fine with that but that's going to have knock-on effects on developers because they're the ones writing the code and therefore the vulnerabilities / bugs. Software engineering would turn into something like civil or aerospace engineering or medicine where where practitioners are required to be certified in various ways, either they or their employers carry liability insurance for bugs they write, and endure onerous processes / audits that their employers and insurers demand of them to reduce the risk of bugs. That I'm fine with too since there's so much crap code being churned out but most software developers probably wouldn't.
- harimau777 2y agoTreat fixing a security issue or implementing a security component the same as implementing a feature for the purpose of raises and promotion.