HACKER Q&A
📣 genmud

How do we deal with the cybersecurity supply chain issues?


SolarWinds and now Ubiquiti have really highlighted how vulnerable we are when it comes to security. They have really highlighted the fact that many companies don't care, intentionally hide/obfuscate their security issues and generally face very little (or no) consequences when it comes to making bad decisions about security.

Of note, Cyberspace Solarium Commission released a transition plan [1] for Biden and there are some great policy recommendations in there. I feel like the only way forward to actually address this is to push for legislation to address these issues.

I have worked in security for about 15 or 20 years now and over the last 2-3 years have become very desensitized/burnt out because most companies just don't have the incentive to do security in an acceptable manner. Sure there are companies that are crushing it and kicking ass but the industry as a whole feels almost like it has regressed. If it weren't for ransomware that actually stops the business from doing anything, I almost feel as though many companies would not do any meaningful investment at all.

[1] Transition Book for the Incoming Biden Administration - https://www.solarium.gov/public-communications/transition-book

Ask HN: What are your thoughts on how we can address or start to chip away at this issue?


  👤 verdverm Accepted Answer ✓
- SigStore / TUF - Look at how Go does security in its module system

Increase penalties so that it gets priority, you point about legislation, is probably the number one way. Or in other words, software needs more regulation

In part it has been a product of the move fast and fix things later, plus how easy it has become to create applications for the inexperienced.

The shortage of developers and new entrants to the field, I suspect, has lowered the average years of experience. Security mindset and understanding all the complex ways that things can and are broken (the security frontier) takes a long time.

Cloud plays into this, more complex and harder to get right, also easy to spin up insecure defaults. (See Helm)

Unpopular idea most likely, but what if creating software was more akin (legally) to doing chemistry than writing books? (Not advocating, just posing a thought experiment)