> You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget the very folks behind code.gov are the same ones that influence who gets contracted with the government...
If you base your "security talent" hiring decisions the same way you approach "contract customer service representative decisions, you'll end up with very pleasant people who don't know jack shit about security. Which would explain a lot of the results we're seeing. So you might be right.
If anyone is reading this thread and wants their software to be actually secure-- no sugar-coating or letting bad decisions happen-- get in touch. :)
> The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.
For once, we are in agreement.
> Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed.
OK, why didn't you do that then?
It's so easy to tell others what to do, when you have no skin in the game. What will you do next time?
- Tell the other person what to do.
- Do it yourself, because it clearly matters to you.
> We need to encourage and support these efforts, not shit all over them.
> In short, don't be an ass... please.
I won't be an ass if and only if folks aren't making demands of how I spend my leisure time.
If you base your "security talent" hiring decisions the same way you approach "contract customer service representative decisions, you'll end up with very pleasant people who don't know jack shit about security. Which would explain a lot of the results we're seeing. So you might be right.
If anyone is reading this thread and wants their software to be actually secure-- no sugar-coating or letting bad decisions happen-- get in touch. :)
> The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.
For once, we are in agreement.
> Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed.
OK, why didn't you do that then?
It's so easy to tell others what to do, when you have no skin in the game. What will you do next time?
> We need to encourage and support these efforts, not shit all over them.> In short, don't be an ass... please.
I won't be an ass if and only if folks aren't making demands of how I spend my leisure time.