The security game is just too fast paced for a profitable business. Until we reach the point where it makes financial sense to move slowly and take extra time to ensure critical business systems are secure, nothing will be fixed.
The security game is just too fast paced for a profitable business. Until we reach the point where it makes financial sense to move slowly and take extra time to ensure critical business systems are secure, nothing will be fixed.
I totally agree that putting more thought and care into software development could certainly be beneficial, especially where security is critical. But I think the point of the article is that an alternative, and maybe more realistic, approach is to make critical systems and networks less brittle so an intentional or unintentional software issue isn't the end of the world. Even in airplanes, computers don't always work right. But it (mostly) doesn't result in planes falling out of the sky because the safety of the system as a whole isn't reliant on one piece of software working perfectly 100% of the time.
It also ignores the point from the article that the solution can't be trying to make all software secure. Whatever the incentive mechanism and whatever the source of the insecurity, it's unrealistic to think we're ever going to be able to make that a reality. But designing the environments software is used in such that broken software isn't the end of the world seems doable, if also incredibly difficult.
For that matter, even considering to use components that unfit for purpose is inconceivable in most professions. Only in software do people use systems with no specifications, no guarantees, and where even the component makers did not intend or design them to be load bearing.
That said, it's often easy things that get the most benefit and we are collectively a long way away from getting the basic security things done properly across the board.
They are already paying for it, and not getting the security.
Particularly in reduced competition due to deep pockets being required to even play the game.
It seems like a fine structure would have to take that into account? Or am I way off base?
We wouldn't have the level of tech we have today if we were to require 'mistakes to be impossible', Rapid growth requires mistakes to be acceptable in some situations.
On the other hand, a quality needs fines. Otherwise, it's too easy to "forget" an inconvenient quality to make a short-term profit (and sometimes compromise users data).
There's certainly degrees of CVE counts and the like, but as long as it's not egregiously worse than everyone else, being the subject of a DEFCON presentation puts you in pretty good company with literally everyone else.
And while there are customers who are aware of things like this and shop accordingly, I'd personally be more concerned about my own reputation damage. It's not the sort of thing I'd like to get questions about in a job interview.
Surely the gov lost a lot of money from this hack assuming they had to hire consultants, ect just to deal with this massive oversight.
The fact solarwinds or equifax exist after such egregious security errors with a botched response at best or an intentional attempt at covering up the size/scope of the problems at worse should tell you everything you need to know.
You can have devs work on bug fixing or you can have them work on features. Whichever brings in more money will be prioritized.