« I'm back! | Main | StillSecure secures an IQ award »

August 15, 2008

If security is a circus, who are the clowns?

bozo Linus Torvalds complains to Ellen Messmer about the "security circus" he sees. Linus is talking about the constant friction between the disclose immediately versus "responsible disclosure" crowd.  While I agree that the when to disclose arguments get tiresome, the long pole in the tent of this circus are the clowns who do a lot of the coding for the products that we use.

With the pressure of getting out code on time and on budget, there are just too many vulnerabilities in the products we rely on.  Racing to get the next greatest feature in this release or that must have functionality that was promised to the customer, too often pushes security and bullet proof code into the shadows.  Then when someone finds the all too often holes in the code, somehow the people finding it are wrong? 

Yes, it would be much better if the whole disclosure timing thing went away. I don't think that will ever happen. But if we had more quality control around code, perhaps it would not be so acute.  So, when talking about the circus, instead of blaming the security people, maybe take a good look at the clowns.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200e5540409958834

Listed below are links to weblogs that reference If security is a circus, who are the clowns?:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005