3 ms·
This is patchwork, at best. It may slightly improve posture...they'll hunt for bugs in already published software, instead of demanding strong security principl
by tikums 12y ago
This is patchwork, at best. It may slightly improve posture...they'll hunt for bugs in already published software, instead of demanding strong security principles for software engineering.
“The software security industry today is at about the same stage as the auto industry was in 1930" ... "it looks fast, goes nice but in an accident you die.” ... "The major shortfall is absence of assurance (or safety) mechanisms in software. If my car crashed as often as my computer does, I would be dead by now.” -- Brian Snow, Former Technical Director of the NSA, We Need Assurance http://www.research.att.com/talks_and_events/2008_distinguished_speaker_series/b_snow/2008-10-15-snow?fbid=VGG7O3cANdm http://www.research.att.com/talks_and_events/2008_distinguis...
“Most programmers think that getting run-time errors, and then using a debugger to find and fix those errors, is the normal way to program. They aren't aware that many of those errors can be detected by the compiler. And those that are aware, don't necessarily like that, because repairing bugs is challenging, and, well, sorta fun.
You are not giving a programmer good news when you tell him that he'll get fewer bugs, and that he'll have to do less debugging. Basically, we still live in the dark ages of programming, not unlike the time engineers were learning about boiler technology by figuring out why a boiler exploded, scalding people to death (remember the Therac-25?). People will probably have to die in order for "software engineering" to be a true engineering profession, instead of the buzzword that it is today. Sad but true.” -- Mathew Heaney
As someone said here on HN, it took two major disasters for people in the Netherlands to build coastal defence structures. We only seem to learn from disasters.
- wglb 12y agoSo how does it work for Google to demand strong security principles of Adobe for their Flash product? Finding 400 game over bugs on their own then telling Adobe about them seemed to get more traction.
- tikums 12y agoExactly. This doesn't seem to be popular around here, but unless secure coding practices are mandated, commercial aspects (first-to-market etc.) will take precedence. This is an industry-wide policy issue. Regulation works -- we should really take a hint from Federal Aviation Regulations.
- wglb 12y agoSo how does it work for Google to demand strong security principles of Adobe for their Flash product? Finding 400 game over bugs on their own then telling Adobe about them seemed to get more traction.
- deleted 12y ago[deleted]
- sjs382 12y ago> This is patchwork at best and may slightly improve posture...they'll hunt for bugs in already published software, instead of demanding strong security principles for software engineering. :s/instead of/in addition to/g The correct approach is to do both.