I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
But in the security industry there are multiple levels of this problem:
- The end user doesn't generally know how hardened the product he buys is
- The manufacturer is rarely certain how high quality the security auditing/services he is buying
- How much to invest in securing a product is not an easy decision.
I'm of course simplifying a lot here, but you asked for the economics of those problems, and hopefully this was interesting to some.
[1] http://www.sfu.ca/~allen/leffler2.pdf [2]https://www.iei.liu.se/nek/730g83/artiklar/1.328833/AkerlofM...