| ▲ | taurath a day ago |
| > Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. I work in secure systems and it’s shocking how many people believe this - the incentives from management are all about it too. |
|
| ▲ | TeMPOraL 15 hours ago | parent | next [-] |
| I'd argue the management has a point there; without a pressure to ship, nothing would ever get released, because computer security has not yet understood the basic concepts that every non-computer security work does: - nothing is, can be, or even should be 100% secure; the optimal rate of security incidents in society is not 0 (with apologies to 'patio11) - security is a simultaneous trade-off against costs and usability, and those two other factors are more important: -- security is achieved primarily through raising costs for attackers to beyond profitability, and reducing impact of such attacks (due to "not in isolation from the world" below, this also mostly translates to costs) -- if "properly secured" (in the current cybersecurity sense) product/service cannot fulfill its function anymore, then you may just as well not make it; either way, no point in paying you for security work - security isn't done in isolation from other systems and the world at large; "if this happens we'll go straight to filing crime report with the police" is perfectly legitimate security measure (even if it works somewhat less well on the Internet); similarly, "this is secured by us having insured against it" is also a valid solution to some security problems |
| |
| ▲ | taurath 4 hours ago | parent | next [-] | | This is all fine and good and the sorts of conversations we were having on tradeoffs like any other engineering org. Theres always been pressure to ship, but now its that various pockets of AI Believers have popped up, egged on by a manic management, containing such beliefs that the code no longer matters, that it’s possible to move fast and fix it up later, human review isn’t important anymore, and that lines of code is a valuable metric. Those running projects with these beliefs are sputtering and producing impressive PoCs that struggle to make it into production - either through underestimating the amount of detail needed to scale, or often throwing away good practices in favor of letting LLMs handle tradeoffs that later make changes slow to a crawl. Theres plenty of good ways to utilize LLMs to speed things up, but so many teams got so incentivized by management to move fast at any cost that they’ve thrown out “load-bearing” good practices for software. That bet hasn't been paying off the way they’d hoped. It’s now clear that they thought they’d be able to massively downsize the engineering orgs. Massive token spend is giving very little RoI and now like other companies they’re trying to rein in the biggest spenders who are often not producing value. | |
| ▲ | Cpoll 5 hours ago | parent | prev | next [-] | | I don't think this is always true; mature security teams consider their threat models. There's just a lot of Schneier groupies in the field as well... | |
| ▲ | deaton 10 hours ago | parent | prev | next [-] | | As much as you're right, the attitude in most software development is not "lets make this as secure as reasonable," it is "lets make this barely functional and then move onto the next thing." | |
| ▲ | NooneAtAll3 13 hours ago | parent | prev [-] | | what's patio11? | | |
|
|
| ▲ | noduerme 18 hours ago | parent | prev | next [-] |
| It's not as if best practices aren't well documented, or as if CVEs don't come out every day, or as if the information is somehow unavailable to even the most junior devs to take basic security measures. Not all hacks are caused by pure negligence, laziness or stupidity, but most of them are. Even a little effort goes a long way. My grandfather spent a couple decades as a builder, ran a construction crew. Whatever the project was, he wanted to know everyone he hired personally was going to reinforce and report to him anything they had the slightest doubt about. "Always hammer in an extra nail" was basically his motto. What we do ain't that different. The difference is that when an apartment building collapses, it's bigger news than when a govenrment database does. |
| |
| ▲ | josephg 15 hours ago | parent [-] | | > The difference is that when an apartment building collapses, it's bigger news than when a govenrment database does. Also when a building collapses, people blame the builders. When software leaks user data, the engineers and companies face no repercussions. | | |
| ▲ | taurath 4 hours ago | parent [-] | | Spain just put in place fines equaling to 30% of revenue for data breaches - that’s the only way to make companies care about it directly. |
|
|
|
| ▲ | duskdozer 16 hours ago | parent | prev | next [-] |
| The incentives from society are all about it. What company has ever faced serious consequences for hacks or data leaks? A cheap fine is just an unlucky cost of business. |
|
| ▲ | gchamonlive a day ago | parent | prev | next [-] |
| I like to think behind every Dev anxious to ship half baked software sits an omniscient middle manager with a vague idea of what the product was supposed to do, maybe |
| |
| ▲ | gspr 18 hours ago | parent | next [-] | | It's worse: it seems like almost every developer on this very site is aspiring to be that middle manager, with LLMs as their underlings. We are headed for scary waters. | | |
| ▲ | asdf88990 17 hours ago | parent | next [-] | | Guess you don’t remember the days of ssl on login pages, ssl strip, exfiltering data via JavaScript prototype pollution, and a million other things like that. Only just when we started to have a resemblance of security we got agile and startups breaking things (making rubbish software to capture a few bucks faster) and now vibe coding and llm assisted hacking. The point of my, arguably rant, is that there is nothing new under the sun. | | |
| ▲ | gspr 17 hours ago | parent [-] | | I'm not sure my worries are assuaged by thr fact that it's been bad before, too. | | |
| ▲ | TeMPOraL 15 hours ago | parent [-] | | It should. We went through couple of cycles of "things are bad, inmates are running the asylum" before, and nothing of consequence happened. The world still goes on. It's not a guarantee this time will be the same - but it should temper the worry somewhat. | | |
| ▲ | lazide 14 hours ago | parent [-] | | Uh, even the database with all the compromising information on everyone with a US security clearance got leaked Previously no one was dumb enough to put that in one electronic database - it was on paper. This is going to get orders of magnitude worse. | | |
| ▲ | TeMPOraL 12 hours ago | parent [-] | | I thought security clearances are a dime a dozen, and "all FBI employees" list is full of administrative work and basically 80% mirrored on LinkedIn? (Yes, the remaining 20% - or however much - leaking is a problem.) | | |
|
|
|
| |
| ▲ | goonersallofyou 12 hours ago | parent | prev | next [-] | | We're already 20 miles off shore and in the typhoon. | |
| ▲ | gchamonlive 15 hours ago | parent | prev [-] | | Nothing new under the sun, it's the banality of evil all over again my dude. We never left scary waters, but they do seem to be growing more agitated. Is this the storm before the storm? |
| |
| ▲ | Bluestein 18 hours ago | parent | prev [-] | | This will all of course end when our AGI lords lovingly manage everything /s | | |
| ▲ | gchamonlive 14 hours ago | parent [-] | | No because it's a problem of human communication. Taking humans out of the loop creates other social problems that have been thoroughly documented in cyberpunk mythology, not actual a solution, just trading one big problem with multiple little ones. | | |
| ▲ | Bluestein 14 hours ago | parent [-] | | Please note the sarcasm.- | | |
| ▲ | gchamonlive 14 hours ago | parent [-] | | Noted, but I think it's important to comment seriously because this is an important topic, sorry I didn't acknowledge the sarcasm, should have opened with something like "I for one welcome our AGI overlords" | | |
| ▲ | Bluestein 14 hours ago | parent [-] | | "All our base are belong to AGI" :) PS. Likewise, apologies, perhaps I was at fault for style: There was an underlying more serious point ... ... that, it is indeed a serious problem, that folks shouldn't be having their souls (or anything else for that matter) crushed, and that it indeed would appear to be an issue of conflicting incentives vs. management.- |
|
|
|
|
|
|
| ▲ | ChrisMarshallNY a day ago | parent | prev [-] |
| I believe the technical term is “Move fast, and break things.” MVP is a huge disaster. I can see it working for applications that don’t process PID, but only an idiot ships data handling software before it’s been dragged through a lot of testing. I tested my app for two years, before finalizing, and an LLM still found a couple of holes (minor ones, but ones I missed). After the DOGE debacle, I suspect that all the previously really secure stuff, is now out there, too. In fact, I wouldn’t be surprised if some of these leaks, came from that. FBI employee data is very bad. |
| |
| ▲ | dasil003 a day ago | parent | next [-] | | The issue is that in consumer and enterprise software, move fast-and-break-things outcompetes secure-by-default every time. Critical infrastructure needs to have a different set of priorities, but it’s very hard because the expertise is so thin on the ground. Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things for $150k a year when they can easily make multiples of that in big software companies that don’t own that level of risk. | | |
| ▲ | generic92034 19 hours ago | parent | next [-] | | The incentives have to change. Any breach regarding PID should have fines as a percentage of revenue of the company. Any breach intentionally covered up and found out later by a third party should mean jail time for the C level. Yes, I know it is hard to make such laws "foolproof". And yes, in the current political and economical climate it will not happen anyway. | | | |
| ▲ | bch a day ago | parent | prev | next [-] | | > but it’s very hard because the expertise is so thin on the ground. This might be part of it... > Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit. | |
| ▲ | lesostep 17 hours ago | parent | prev [-] | | The real problem is that even for companies that wish to pay more and wait more for secure-by-default can't easily tell the difference. The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code/checksum on an air-gaped computer. We somehow moved to "trust more" in the last decade, and now we can trust nobody | | |
| ▲ | AlotOfReading 15 hours ago | parent [-] | | I've yet to see any form of certification or paid code review I'd be willing to bet critical infrastructure on. And working in safety critical software, that's not for lack of trying. Good review is usually harder than building a working system and the asymmetry of offense and defense applies to anything you miss. |
|
| |
| ▲ | parineum 21 hours ago | parent | prev [-] | | If DOGE is going to have an effect on network security, it's not going to be for many more years. | | |
| ▲ | ChrisMarshallNY 19 hours ago | parent [-] | | Not really. It’s likely that the dumped (and compromised) data might contain things like keys and URLs that could be used to pry open other sites. Blackhats have become really good at following breadcrumb trails, and using “innocuous” clues to ascertain much more dangerous access. LLMs have been a huge force multiplier. Here. If that data got out (which probably happened within hours of the data being dumped to insecure storage), then it’s probably already been analyzed and used to leverage access. | | |
| ▲ | parineum 5 hours ago | parent [-] | | That's an awfully exciting narrative you've spun. | | |
| ▲ | ChrisMarshallNY 4 hours ago | parent [-] | | Not really. It's par for the course. I didn't say anything that isn't common knowledge. Why are you so interested in defending DOGE? |
|
|
|
|