| ▲ | dasil003 a day ago | |||||||
The issue is that in consumer and enterprise software, move fast-and-break-things outcompetes secure-by-default every time. Critical infrastructure needs to have a different set of priorities, but it’s very hard because the expertise is so thin on the ground. Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things for $150k a year when they can easily make multiples of that in big software companies that don’t own that level of risk. | ||||||||
| ▲ | generic92034 19 hours ago | parent | next [-] | |||||||
The incentives have to change. Any breach regarding PID should have fines as a percentage of revenue of the company. Any breach intentionally covered up and found out later by a third party should mean jail time for the C level. Yes, I know it is hard to make such laws "foolproof". And yes, in the current political and economical climate it will not happen anyway. | ||||||||
| ||||||||
| ▲ | bch a day ago | parent | prev | next [-] | |||||||
> but it’s very hard because the expertise is so thin on the ground. This might be part of it... > Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit. | ||||||||
| ▲ | lesostep 17 hours ago | parent | prev [-] | |||||||
The real problem is that even for companies that wish to pay more and wait more for secure-by-default can't easily tell the difference. The only solution I can come up with is some form of certification or paid code review from a third party. I know that at least for Windows prior to 7 Microsoft actually allowed some parties to come in and check the code/checksum on an air-gaped computer. We somehow moved to "trust more" in the last decade, and now we can trust nobody | ||||||||
| ||||||||