The Reason Software Remains Insecure
I spent lots of time on typography, so you should read this article in its original form at The Reason Software Remains Insecure
There are myriad theories as to why software remains insecure after we’ve spend decades trying to solve the problem.
Some say it’s the lack of will to secure things, the lack of vendor liability, the insecure languages we use, insufficient developer training, not enough security products—and the list continues…
But there’s a far simpler and more powerful explanation, which is best demonstrated in a visualization like the one above: the existence of insecure software has so far helped society far more than it has harmed it.
Basically, software remains vulnerable because the benefits created by insecure products far outweigh the downsides. Once that changes, software security will improve—but not a moment before.
Consider the mystery solved.
These failures are likely to start, by the way, largely due to the explosion of the Internet of Things.
When we start having complete and long-lasting internet outages, companies being knocked offline for days or weeks and going out of business, and—most importantly—large numbers of people dying, then we’ll see a serious push for secure software.
In the meantime, quickly developed, quickly deployed, and insecure code will continue to perform miracles for human civilization, and will therefore continue to be welcomed into businesses and society.
In short, don’t expect change until we see the downsides of insecure software start to rival the benefits. And it’s currently not even close.
I spend between 5 and 20 hours on this content every week, and if you're a generous type who can afford fancy coffee, please consider becoming a member for just $5/month…
Thank you,
Daniel
Daniel Miessler's Blog
- Daniel Miessler's profile
- 18 followers
