Security? Who cares...
Over the weekend I was running some errands and made a
purchase with my credit card. The cashier did her normal glance at the back of
the card before proceeding on with the transaction. Now rather than signing the
back of my credit card, I instead write "See Driver's License"; the
hope is that the cashier will verify against my driver's license that I am
really me instead of an imperfect signature comparison. Unfortunately only 25%
of the cashiers ever ask to see my license. I'll even watch them flip the card
over, read what I wrote, and then continue on as if there's no problem.
This got me thinking about security in general and web
application security in particular. The cashier is part of a group of people
who are on the front line of security and more than half of them don't care
enough to enforce the policies. If we can't get the front line whose job it is
to care to actually care, then what are the chances of getting someone who is
more indirectly involved to care? Most developers are more worried about the
functionality of what is being built than the security. Sure, they care but
only so much as it's easy to integrate. If it involves heavy lifting, then it's
easier to focus only on the feature set and ignore security.
At least until something blows up and security becomes the feature set.
-



Recent Comments