4 ms·
It suggest that insecure software should be simply called defective product. So the security audit should be called QA. A product, which don't spend a lot on Q
by ezoe 2y ago
It suggest that insecure software should be simply called defective product. So the security audit should be called QA.
A product, which don't spend a lot on QA, profit more. Unless there will be a catastrophic incident.
Also, why haven't those so called security researchers jointly criticized EDR yet? A third-party closed source kernel driver which behave like, practically same as malware.
- Thorrez 2y agoSoftware has tons of bugs. A fraction of those bugs are security vulnerabilities. Any type of bug can be considered a defect, and thus can be considered to make the product defective. By using the terminology "defective" instead of "vulnerable" we lose the distinction between security bugs and other bugs. I don't think we want to lose that distinction.
- irundebian 2y agoSecurity-related product defect, or simply security defect.
- acdha 2y ago> Also, why haven't those so called security researchers jointly criticized EDR yet? A third-party closed source kernel driver which behave like, practically same as malware. They have been, for years. Some very prominent voices in the security community have been criticizing the level of engineering prowess in security tools for ages - Travis Ormandy ripped into the AV industry for Project Zero over a decade ago and found critical problems in things like FireEye, too. The problem is that without penalties, the companies just keep repeating the cycle of “trust us” without improving their levels of craft or transparency.
- specialist 2y agoEmpathic agreement. Source: Was QA/test manager for a bit. Also, recovering election integrity activist. TIL: The conversation is just easier when bugs, security holes, fraud, abuse, chicanery, etc are treated as kinds of defects. Phrases like "fraud" and "exploit" are insta-stop conversation killers. Politicians and managers (director level and above) simply can't hear or see or reason about those kinds of things. (I can't even guess why not. CYA? Somebody else's problem? Hear no evil...?) QA/Test rarely receives its needed attention and resources. Now less than ever. But advocating for "fixing bugs" isn't a total bust.
- Terr_ 2y agoIn terms of shaming bad products, motivating executives, etc, maybe... However I don't think you can easily combine general QA and security stuff under one roof, because they demand different approaches and knowledge sets.