Earlier quoted context omitted.
> She's blaming the software industry and software failure. That's Apache, and Struts. I interpret her differently: > There are technical factors that explain why cybersecurity is so weak, but the underlying reason is political, and it’s pretty simple: Big corporations have poured large amounts of money into our political system, helping to create a regulatory environment in which consumers shoulder more and more of…
>software businesses (and the technology sides of other companies) have acquired perhaps the greatest degree of impunity. TIL: No warranty == impunity. Nobody MADE Equifax use Struts. The source is open to inspection. The bug existed there for 8 years. Let's see how many audits Equifax did on the source code with no warranty. >If the costs of failure in production due to bugs were higher, businesses would make differ…
I see you equating Struts and software practices with the businesses that use software. I see those as two separate things.
> Nobody MADE Equifax use Struts.
Yup.
> The source is open to inspection.
Yup.
> Let's see how many audits Equifax did on the source code with no warranty.
I'm not sure why you're including this. I think they should have done source code audits in accordance with how they weighed the costs/revenues. Do you disagree? I personally tend to lean towards more tests and code analysis, but I understand others weigh this differently.
> If the costs were higher, the one poor guy working on Struts would do a better job? No, I think that guy would probably not write the software.
I place the responsibly with the company using Struts in their product, not the Struts dev. I'm not sure how you're getting the impression I (or Zufrekci, for that matter) place this on the Struts dev. I'm responsible for the results of the applications I put into production, including the libraries I choose to use in that application. I don't hold generally hold the devs who wrote those libraries responsible.
Like I said, I think we're talking past each other. I still think you're reading too much into (and too little close reading of) Zufrekci, but I'm not sure how better to express what I'm trying to say. I've now read the piece through 3 times fully and I really don't see her making any of the points you're arguing against.
If you've got specific questions about what I've written, please ask. Otherwise, I'll sign off. Have a good evening!