| ▲ | josephg 13 hours ago | |||||||
> Generally it also takes consulting with maths experts who have spent their life studying cryptography and as such command a decent wage. It doesn't take a maths degree to look out for SQL injection attacks or to audit software & write up a risk assessment. | ||||||||
| ▲ | goonersallofyou 12 hours ago | parent | next [-] | |||||||
There's very little, if any, incentive to do anything more securely than absolutely necessary. It is only a problem, when it is a problem and is treated that way in nearly every org I've worked in. | ||||||||
| ||||||||
| ▲ | jfyi 12 hours ago | parent | prev [-] | |||||||
I agree that security isn't bottlenecked by our ability to learn. We generally fail at the grit needed to do it day after day, especially when the benefits aren't immediately visible. | ||||||||