news.volyx.in

The Insecurity Industry (edwardsnowden.substack.com)

743 points by stanislavb · 1886 days ago · 368 comments on HN

Article summary

The article discusses the insecurity of the software industry, highlighting the lack of liability for bad code in commercial products. It also touches on the idea that diversity can help improve interoperability and security. The article is not available, but the comments suggest it explores the tension between security, profitability, and monoculture in the tech industry. The discussion around the article reveals concerns about the industry's priorities and practices.

Main themes

  • software security
  • industry liability
  • monoculture vs diversity
  • formal methods
  • engineering standards
  • profitability vs security
  • regulatory frameworks
  • tech industry practices

What commenters say

  • Implementing legal liability for bad code in commercial products could improve software security.
  • The software industry prioritizes speed and profitability over safety, security, quality, and maintainability.
  • Diversity in software development can lead to better interoperability and security, but may come at a cost.
  • Some argue that software development is not a real engineering field due to the lack of rigorous standards and liability.
  • Others propose that formal methods and languages like Liquid Haskell could bring more rigor to software development.
  • The idea of holding companies liable for bad code is met with skepticism, as it could drive companies to jurisdictions with more lenient laws.
  • There is a perceived trade-off between security and the cost of software development, with more secure software being more expensive.
  • Some commenters believe that the industry's focus on speed and profitability is driven by the desire to get to market quickly, rather than a lack of willingness to invest in security.