• runswithjedi@lemmy.world
    link
    fedilink
    English
    arrow-up
    85
    ·
    2 months ago

    If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.

    I respect this. I’d be very happy if my boss told me this and I would feel empowered to build great products. I hope this sentiment spreads through the industry.

  • ooterness@lemmy.world
    link
    fedilink
    English
    arrow-up
    37
    ·
    2 months ago

    Incentives like this are tricky. You can reduce the numbers by fixing the problem, or by sweeping it all under the rug. Guess which is easier to do on a quarterly basis?

  • mansfield@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 months ago

    Seems best to do this after firing the first 2-3 levels of leadership since this whole mess was created under their watch. Maybe the next thing to do is to ask if the US government wants to so heavily depend on a company that is no longer a US entity.

    Microsoft is overwhelmingly Indian contractors now. Infact much of the large legacy US tech companies have done so much offshoring I’d hardly call them US companies anymore. Are these companies really who we want to stake our national security on?

  • e0qdk@reddthat.com
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 months ago

    I wonder if this will actually cause an increase in the number of security vulnerabilities and breaches as there’s now a fairly obvious way for employees to penalize their bosses financially for being assholes…

    • taanegl@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      That exactly it. M$ execs look at this stat and probably go “we need to make it more unsecure, for the shareholders - of course.”

    • juli@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 months ago

      They fired their testers long ago who might’ve caught that. So ya. I can totally see that happening