| ▲ | pixel_popping 5 hours ago | ||||||||||||||||||||||
Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about. Common recklessness obviously include devs running binaries on their work machine, not using basic isolation (why?), sticky IP addresses that straight-up identify them, even worse, using same browsers to access admin panels and some random memes, obviously, hundred more like those that are ALREADY solved and KNOWN by the developers themselves. You literally have developers that still use cleartext DNS (apparently they are ok with their history accessible by random employees outsourced) | |||||||||||||||||||||||
| ▲ | snovymgodym 4 hours ago | parent | next [-] | ||||||||||||||||||||||
> it mostly boils down to recklessness of developers I disagree. I think in big tech and the corporate world, it boils down to the organization fundamentally not valuing security and punishing developers if they "move slow", which is often the outcome when you maintain a highly security-oriented process while developing software and infrastructure. When big leaks happen, the worst that occurs is that some trivial financial penalty is applied to the company so the incentive to ignore security problems until you're forced to acknowledge them is high. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | giantg2 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
"Cybersecurity is taken too lightly and it mostly boils down to recklessness of developers, they are just "praying" that no-one act on the issues they already know and it's something we must start talking about." I agree that cyber security is taken too lightly. However, I think that many developers don't actually know about vulnerabilities. In many companies those reports get filter through other teams and prioritized by PMs. The devs tend to do their best at meeting the afressive schedules the penny pinching business people set. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | LunaSea 4 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Highly disagree. It's most of the time a question of management not caring about security or disliking the inconvenience that security can bring. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | causal 5 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Totally agree, though I'd argue that it's still a software failure if preventing exploits requires every user memorize and follow an onerous list of best practices. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | matheusmoreira 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
> recklessness of developers Nah. It's the corporations that could not care less and therefore do not reward careful work. They care about nothing but time to market. Start stacking legal and financial liability and I guarantee they are suddenly going to start caring a lot. | |||||||||||||||||||||||
| ▲ | 5 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
| [deleted] | |||||||||||||||||||||||
| ▲ | sdwr 4 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Recklessness is based on effort, likelihood, and consequence. If you live in a small town, you might not lock your front door. No matter where you live, you probably don't lock your second floor windows. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | MrDarcy 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
I read your list and all of that is normal computer use. How can it be reckless to use a computer normally? | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | jacquesm 4 hours ago | parent | prev [-] | ||||||||||||||||||||||
You missed the management factor. And even if managers don't explicitly ask you to build insecure stuff they will up to the pressure to the point that you have no choice or leave the company for someone who will do just that. So the end result is the same. Rarely will individual push back with some force and then they will eventually be let go because they're 'troublemakers'. | |||||||||||||||||||||||