TheWesDude
Sonny, I Watched the Vault Bein' Built!
korindabar said:Don't confuse what I'm saying. I'm not saying they aren't criminals and I'm not saying they shouldn't be caught and brought to justice. Perhaps I have a more personal interest in their shenanigans because I've done a lot of work with web security in particular. I can point to their pastebin entries and say, "Look, that's what happens.".
Just within my own company I've reported serious vulnerabilities in our platform to management and engineering teams and it would take months for them to roll out a service release for it or consider it anything higher than low priority.
and here is why there are so many of these flaws.
it would take a lot of effort to fix all these problems and fixing problems does not really bring in income as much as the next version would.
so rather than management making security a real concern, they say "oh well, we will patch it eventually but we need feature G added to the software and we can sell more copies!"
patching and bugfixing does not generate more income. problem is eventually you wont have income because nobody will want your product with numerous well known security flaws.
i have lots of stories about issues like this.
your dev team can spend 6 months squashing bugs and closing security loop holes, or spend 6 months working on the next version of the software and maybe incorperate some of those fixes in that. ask a manager which he would rather do.
ask an accountant which would help their bottom line more.