Skip to content

Comment on Ask HN: Why do you think vulnerable code is still being released today?

Comments

The first and obvious reason would be that developers and companies alike simply don't have the skills/mindset or don't care, must rush to release code, etc. It becomes an afterthought (usually after something bad happens).

I would say the second reason is very similar but applies to frameworks. Developers usually choose a framework and think they are done. This is something quite difficult to fight. So if frameworks would be more careful with security by default, the net result throughout the industry would be greater than the uphill battle of educating developers on security.

Microsoft has an internal term for something like this that they apply to Visual Studio (I forget the specific term) but it's something like ensuring the common path to do something automatically ensure best practices will be followed. That by using VS, you would have to go out of your way to do something outside those best practices. I think this works for the general population of developers.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.