Earlier quoted context omitted.
I have read through every comment here, and fail to see a lack of self-awareness in any of them. Perhaps you are seeing things from a perspective I have not considered...or you are boldly trolling from a throwaway account. If it is the former, please elaborate.
I suspect it has something to do with tptacek's very strongly pro-US-state political views and his dismissive attitude to people who don't share those views, as demonstrated in the above comment.
Infosec's Jerk Problem (2013)
101–110 of 142 posts
Re: Infosec's Jerk Problem (2013)
#102Re: Infosec's Jerk Problem (2013)
#103InfoSec: "There is a vulnerability." me: "PR or GTFO." The problem described is that ISOs are professional nags instead of software shippers.
That only works if your application is simple enough for the infosec folks to know how to write a patch for it. If the organization has 200 of those apps, it's unlikely a transversal security team is able to write patches for each one of them.
Re: Infosec's Jerk Problem (2013)
#104The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…
Re: Infosec's Jerk Problem (2013)
#105Earlier quoted context omitted.
This. If the Mossad/NSA/PLA thinks there is anything of value on our network, they either already have it or could trivially get it. It wouldn't be the end of the world if they had it, so I don't really care.
Yep, within reason - I don't buy into the "I have nothing to hide argument, so I have nothing to worry about." People like Trump or UKIP remind should remind us of the danger of that. Though we should remember, in a realpolitik world, the long-term interests of the NSA -> US Gov -> West etc is in supporting democracy activists for example. It's just a pity that the sensationalism of "counter-terrorism" interests in t…
Re: Infosec's Jerk Problem (2013)
#106Help them to be excited to work with you, rather than to turn the other way when they see you in the hallway.
The mentioned topic of "Recalibrate 'urgent'" is a great message. We're rapidly approaching a desensitized feeling of security risk within organizations and in the general public. As breaches/incidents continue to rise we'll approach a "who cares?" level from the public.
What can they do? Steal my CC? Already been stolen. Steal my SSN? Already done.
What's left to fear when privacy is gone?
What really keeps me up at night is when security incidents are measured in lives. Scary...
Re: Infosec's Jerk Problem (2013)
#107The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…
I'm suspect not.
No matter how much time you have, it's more exciting to work on something new than going through testing. Time is not all equal. Even if you have an unlimited supply of time (everlasting life), you cannot somehow use a time block that occurs 1000 years from now, in order to displace the boredom you feel from what you're doing now.
If anything, unlimited time will increase procrastination. "If this isn't debugged for another 500 years, that's okay; I will live long enough to see it debugged.".
Thus, I suspect, most developers would actually love to have a vast army of other people with unlimited time to do the QA to make sure their code is secure and well-tested. :)
Re: Infosec's Jerk Problem (2013)
#108Coming into meetings with other teams with a list of (often unfounded) assumptions does not help anyone. I wrote about this a bit last year: https://blog.conjur.net/devops-and-security-the-five-monkeys
Re: Infosec's Jerk Problem (2013)
#109The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…
Until companies start being held liable for their software deficiencies there won't be a change. This is also why I find "Software Engineering" a joke. The equivalent of what passes for Software Engineering, in any other engineering field, would put people in prison.
What we actually see is a lot of apologizing, recalls and class-action suit settlements, and nobody actually seems to go to jail.
Not all engineering is about bridges not collapsing; conversely, there is some software that is equally safety-critical and carefully developed.
There is also "everyday engineering", like in consumer products. That's a category that fails miserably. Put simply, shit breaks. Past the one year warranty? Too bad!
Re: Infosec's Jerk Problem (2013)
#110One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…
What happens if your security program is really really really effective?
Answer: Nothing