DEV Community

Discussion on: Treat security as a risk

Collapse
 
jpaulin profile image
Jukka Paulin

Loved this piece!

I quote from my unfinished B.Sc. thesis for the financial aspects of security:
Security breaches are enabled by many things, but one of the
factor that creeps from human assumptions is that the software
team responsible for developing the code might never imagine
the software to be used in a particular setting.

"Small web servers", which were supposed to live for a few months, then one day find their way not only to rather closed and protected intranets, but indeed are out in the wild, facing all the hostile network traffic the world of Internet can bring about. These same software are also running perhaps as a utility glue in children's toys and what-not - essentially in as many places as you could NOT imagine. People might have forgotten (during a typical lifespan of 5-10 years) the origins of the software, and might take for granted certain security properties - "since it (software) is popular and has been time-tested".