4 ms·
Because its a technical guarantee. How is a product manager going to able to personally approve code he can't even read?
by UK-AL 2y ago
Because its a technical guarantee. How is a product manager going to able to personally approve code he can't even read?
- deleted 2y ago[deleted]
- lores 2y agoI'd argue there are vanishingly few engineers who understand all the consequences of even relatively simple code in terms of security and reliability. Every time there is a security breach at a bank or FAANG, some very smart and experienced engineers with the backing of the business didn't understand something. It's downhill from there for most everyone else.
- int_19h 2y agoI'd argue that if there was a demand for software correctness - motivated by, say, legislation applying some baseline standards on such in sensitive applications like money processing - we'd have a lot more smart and experienced engineers focusing on security in particular. The way things are now is because we as an industry have decided that "move fast and break things" is acceptable, and our culture reflects that. So we need to change the culture.
- gorft 2y agoThen maybe those developers shouldn't be employed. Most of us can't do brain surgery, and yet society trundles on without a million people running around poking frontal lobes. "But I really wanna!" has never been a qualification for any job in the history of jobs.
- blackbear_ 2y agoBut it is literally the PM/PO's job to establish and prioritize product features and timelines. If security is a priority, then it should be communicated and prioritized appropriately instead of being always set back in favour of shiny new features, as it often happens.