Earlier quoted context omitted.
Why do you think it is badly constructed?
It's too detailed and it has an agenda.
Poll: Does your startup try to write secure software?
11–18 of 18 posts
Re: Poll: Does your startup try to write secure software?
#12I'm eager to see what people here have to say about this poll, but it's so badly constructed that I'm not hopeful about the quality of the results. I've thought about posting a similar poll, but it would be self-serving.
If you do, I can ask the moderator to delete this one.
Re: Poll: Does your startup try to write secure software?
#13Earlier quoted context omitted.
It's too detailed and it has an agenda.
That is because english is not my native language and I didn't know how to explain it better.
Re: Poll: Does your startup try to write secure software?
#14Earlier quoted context omitted.
That is why I have placed that introduction. If this news recommendation site is being constantly hacked to the point in which it has more malware than a porn site, then the developer should consider making it more secure. Otherwise users would not visit it anymore, unless the owner starts to place some hot picures to serve together with the exploits.
That's nice. In reality, the security quality of a typical web application is quite low, especially compared to F500 enterprise standards --- few would survive a pentest. And yet most of them are not hacked in that manner. Indie developers need to get better at writing software that is secure by default, but they do not need the whole process-driven juggernaut that Microsoft runs internally with things like SWI. So,…
The guys at Wordpress and Jommla beg to disagree.
It depends on how popular it is. If the open source version of Reddit becames as popular as Wordpress, then it certainly would get hacked in that manner.
Re: Poll: Does your startup try to write secure software?
#15Earlier quoted context omitted.
That's nice. In reality, the security quality of a typical web application is quite low, especially compared to F500 enterprise standards --- few would survive a pentest. And yet most of them are not hacked in that manner. Indie developers need to get better at writing software that is secure by default, but they do not need the whole process-driven juggernaut that Microsoft runs internally with things like SWI. So,…
>>And yet most of them are not hacked in that manner The guys at Wordpress and Jommla beg to disagree. It depends on how popular it is. If the open source version of Reddit becames as popular as Wordpress, then it certainly would get hacked in that manner.
Re: Poll: Does your startup try to write secure software?
#16Earlier quoted context omitted.
That is because english is not my native language and I didn't know how to explain it better.
No, it's because you provide a choice between "we have a process that includes threat modeling..." and "we have no process", thus excluding the vast middle ground of people who care about security but don't hire consultants.
You just need to think about the security implications of what you are going to to, do it keeping in mind all that could go wrong, check again what you have done, and keep a spreadsheet registering how well you are doing. And do it systematically.
Re: Poll: Does your startup try to write secure software?
#17Earlier quoted context omitted.
No, it's because you provide a choice between "we have a process that includes threat modeling..." and "we have no process", thus excluding the vast middle ground of people who care about security but don't hire consultants.
You don't need to hire consultants to have a process. You just need to buy a book or read it for free in the internet. You just need to think about the security implications of what you are going to to, do it keeping in mind all that could go wrong, check again what you have done, and keep a spreadsheet registering how well you are doing. And do it systematically.
Re: Poll: Does your startup try to write secure software?
#18Earlier quoted context omitted.
>>And yet most of them are not hacked in that manner The guys at Wordpress and Jommla beg to disagree. It depends on how popular it is. If the open source version of Reddit becames as popular as Wordpress, then it certainly would get hacked in that manner.
Do we have to spend time pointing out the differences between WordPress and indie startups like Backtype, Songkick, and Adpinion? Microsoft spends a lot of time on security too, and I'm not saying they're dumb for doing it.
Most startups aren't indies.
For instance, Plentyoffish.com was a ONE person startup not so long ago with revenues of 1MM and 1B pageviews. Just imagine what a news recomendation site with TWO persons would be able to do. :)