← Back to context

Comment by dasil003

1 hour ago

The issue is that in consumer and enterprise software, move fast-and-break-things outcompetes secure-by-default every time. Critical infrastructure needs to have a different set of priorities, but it’s very hard because the expertise is so thin on the ground. Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things for $150k a year when they can easily make multiples of that in big software companies that don’t own that level of risk.

> but it’s very hard because the expertise is so thin on the ground.

This might be part of it...

> Why would anyone with the expertise to make these calls bang their head against the wall trying to educate bureaucrats about these things

But I suspect this might be most of it: good engineering is boring (to the recipient). Preemptively solving problems gets no credit.