Comment by tumetab1
5 hours ago
I sympathize with the sentiment but the suggested/implied guidance to fix bugs is wrong.
The overall game is increasing costs to exploit so much that attackers give up. Fixing 10 most obvious bugs, just very slightly increases costs, they would just a few more tokens to find another bug.
As someone said "I had infinite bugs, I fixed 1000, I still have infinite bugs".
To significantly increase exploit costs software/security has -1 years to do:
- Defense in Depth - Sandbox everything - Zero trust - Canary tokens - Split data from code (lol) - App Whitelisting - Reduce attack surface - Etc.
In other words, the only path is investing heavily on the "game changers" we have already discovered... but we are too cheap/lazy/coward/incompetent to apply.
And if we feel specially brave, changing the liability laws regarding software. Open Source & Proprietary code is so crappy because no gets jailed or fined when one of its dumb decisions results in millions of people have their data stolen.
No comments yet
Contribute on Hacker News ↗