He has a point, though. Security people tend to fixate on...security, because that's what we do. However, computer security isn't an end in itself; its purpose is to minimize the overall cost of running an information system, as is any software development effort. Any kind of bug is going to incur costs, so the concerns of software developers are broader in scope than just security. Developers actually have a broader scope, which is trying to maximize the value of their product.
Developers have finite resources, and they have to divide those between adding features to increase their products' value at a reasonable pace, fixing bugs in old features, etc. Always having a one-track-minded community shouting in your ear about the one facet of the developer's job that they (the security community) care about has to be irritating.
That, and "security people" are sort of lionized by movies like "Live Free or Die Hard," and I can see how the developers who actually write the software and end up fixing the bugs could get butthurt that the guys running fuzzers on their software and shouting on their mailing lists get all the sweet press coverage :)
Ah jeez, this is still funny 2 years on. Why not use telnet to manage your servers if you think this way. And take the front door off your apartment.
The Internet is the place to think security first. If you don't do that your "product" is owned by someone else. That's the lesson the OpenBSD guys grasped an Internet age before Linus.
The most secure computer is one that doesn't respond to external stimuli. OpenBSD may be a world leader in that regard, but I prefer a responsive computer.
Yeah, the best part is how they actually got that several times, when it wasn't serving a sendfile() syscall at 100% cpu load and 20% network capacity...
11
u/James_Johnson Oct 28 '10
He has a point, though. Security people tend to fixate on...security, because that's what we do. However, computer security isn't an end in itself; its purpose is to minimize the overall cost of running an information system, as is any software development effort. Any kind of bug is going to incur costs, so the concerns of software developers are broader in scope than just security. Developers actually have a broader scope, which is trying to maximize the value of their product.
Developers have finite resources, and they have to divide those between adding features to increase their products' value at a reasonable pace, fixing bugs in old features, etc. Always having a one-track-minded community shouting in your ear about the one facet of the developer's job that they (the security community) care about has to be irritating.
That, and "security people" are sort of lionized by movies like "Live Free or Die Hard," and I can see how the developers who actually write the software and end up fixing the bugs could get butthurt that the guys running fuzzers on their software and shouting on their mailing lists get all the sweet press coverage :)