Bad software keeps cyber security companies in business
dogesec.com
dogesec.com
This post focuses more on hard-coded credentials, which are absolutely a problem, but seemingly glosses over the difficulty of programmatic secrets management in an organization. Sure, GitHub secrets are perfectly functional…until they end up hard-coding themselves into your pipeline on accident, at which point you get to spend a lot of time and money setting up HashiCorp Vault or similar. That goes great until human error meets the complexity of modern security software and development best practices, at which point human error wins again.
I would argue it’s not merely bad software from non-security companies, but also bad software calling from inside the house (said security companies). Bad agents that hoover up CPU cycles, feature overlap tangling themselves into knots with other programs, and products so complicated that nobody short of a mathematician and Cybersecurity expert could ever hope to comprehend what the various toggles and options are for, or whether it was deployed properly and securely.
Over on Mastodon, I gave a shoutout to the ACME-bot team for actually meaningfully advancing the state of security by making PKI as easy as 1-2-3 for most deployments; this is the security model we should be championing if we want a more secure environment. We need to promote simplicity and security over complexity and legacy support, or we’re forever going to be chasing down human error.
People have this odd framing where software mistakes are more basic and common than any other type of building. If you were able to do a similar audit for anything, you would see a growing number of seemingly basic things that are done wrong.
Which isn't to say that we shouldn't do what we can to make things better, of course. It would be nice if we weren't trying to connect more and more of our systems together, though.
The only thing I have to add is that this same concept applies to just about everything -- it isn't just a cybersecurity industry problem.
- Bad writing keeps Grammarly in business - Developers doing a bad job at confirming to a codebase's style guidelines causes code linters and formatters to stick around pervasively - Bad authentication and authorization practices keeps Okta/Auth0 in business - ... <the list goes on and on>
Or is it just move fast and leave things broken mindset?
In the metapher with your house, that would be like building an always open back entrance, because building the house is easier with that always open back entrance.