3 ms·
> Right now I would not trust any sensitive, personal information to any website or cloud service. A friend of mine put together an open source project that us
by SomeCallMeTim 14y ago
> Right now I would not trust any sensitive, personal information to any website or cloud service.
A friend of mine put together an open source project that uses cryptography to store your data in the cloud securely, so it's certainly possible. [1]
It's also possible to write complex software and not be vulnerable, though 99.999% of the time companies (start-ups and otherwise) seem more concerned with an MVP and new features than security. If you design a system from the ground up with security as a core feature, then you have a CHANCE of having a system that won't be vulnerable to script kiddies every other week. On top of that you need to be sure to protect against social engineering, but that's another discussion.
I don't even know if it's possible to use something like Rails (or Ruby, even) and be secure for the long term without having to deal with constant updates and patches. On the other hand, I HAVE used complex systems that were designed from the ground up to be secure and that simply NEVER turned out to have a security vulnerability after the first few releases. (Anything by DJB, for example. [2] Some of those tools have gone 15+ years with no vulnerabilities. Compare the constant sendmail or bind security exploits, numbering in the hundreds at this point, to DJB's qmail and djbdns.)
Until it's a priority, it's always going to be an afterthought, by definition. People will use Rails or the framework du jour, despite the fact that such frameworks are designed with the same "get it done and release ASAP" philosophy that most commercial sites are developed with, and then everyone wonders at security holes. Sigh.
[1] https://tahoe-lafs.org/trac/tahoe-lafs https://tahoe-lafs.org/trac/tahoe-lafs
[2] http://cr.yp.to/ http://cr.yp.to/