I have no security education, but I care about stuff because I will be held responsible if we get pwned at some point.
IMO the biggest issue is that SWEs very rarely have long term skin in the game in the projects they are committing to.
Many have strong incentives to not care about security, day 2 ops, etc... When shit hits the fan bonuses were already paid and said professionals often moved on.
I think that tends to be lessened by having small projects with clear owners that don't jump around all the time. Companies with smaller turnover win big here.
I find it helpful to have standard low cost (certainly no monetary cost, but also little in the way of bureaucratical cost) solutions which remove the need.
E.G.
"I need to access this device's webpage from everywhere"
"Fine, go via this proxy which has oidc integration with our corporate identity, Here's the URL, let me know if there's any problems"
Doesn't always work, but it certainly reduces the fights.
(Side rant, the fact that academic computer science is so far away from real life is yet another can of worms)
It would increase the barrier to releasing software massively (possibly killing the startup scene altogether), but it doesn't mean software development would end.
Good.
It won't take years. We will have to train developers and create better tools. Then you will libraries and apps sandboxed, like we would not allow an IDE full access to the internet, or to the entire hard drive without permissions.
Say you get the task to build an RSS reader, you will have to choose:
1 use a language+standard library that is safe and the vendor offers some warranty
2 use an unsafe language or some unsafe libraries but you will have to take the risks and do the work to review and evaluate
3 in case you prefer open source you find a language and ecosystem where there is some foundation that even if it can't offer some warranty it accepts donations and contributions that are directly targeted on security, so you would have packages that would have a checkmark that was reviewed by a team.
So I would use a safe language(a GC one) with a trusted standard library, so now I can do the network requests to grab the XML files , parse them with the secure XML library and render the content in the safe Web View provided.
This means that the guys that give or sell me the XML library and the Web View will take the risk, but they can charge for their work. We would probably get smart developers using some extremely safe languages like math safe not Rust(safer then C safe) and this guys can write a maybe slower but 100% web view (maybe with less shiny animations).
Capitalism would be forced to invest in this safer tools and in training the developers, Microsoft ,Apple, Google will have to secure their unsafe OS and libraries but for sure it would not take 1 guy years to build an RSS reader that would not take over your data and send it to some hacker somewhere.
The fact that doctors are relatively frequently sued in the US is one of the reasons why US has very expensive healthcare. If you are rich that's fine, but almost everybody else would prefer more available (cheaper) healthcare with doctors who don't need to spend money on liability insurance.
"I'll have some Beware-of-the-Leopard signs printed up."
If anything, freeware (whether open source or proprietary) should be exempt from costs. You get what you pay for, after all.
How to create this incentive is an open question but more laws and regulation doesn't look like a good answer to me.
The solution is simple: similar in thought to GDPR, make vendors of proprietary products above a certain size (e.g. market share, net worth, # of employees) liable for security issues even if they do not result in privacy breaches.
Vendors will then either have to release their software as open source or need to carry insurance for security issues, and the insurance companies will only provide insurance if company processes are following industry standards - e.g. code reviews, security audits during concept and development, appropriate staffing of developer teams or requiring certifications/training for developers.
I think ultimately PM takes care of which fix/feature to be worked on?