CISA boss: Makers of insecure software are enablers of the real villains

https://www.theregister.com/2024/09/20/cisa_sloppy_vendors_cybercrime_villains/?td=rt-3a

3 Comments

  1. You won’t fix that problem until the cost of a breach exceeds the cost of writing good software.
    Why am I going to put more than the minimum effort in, when all a breach costs is a bit of bad publicity and some credit monitoring ?

  2. Insecure, lazy software keeps cyber villains occupied with financial crimes, so it should be easier for gov. to design more advanced systems that are practically impenetrable, for use with important infrastructure and military. OTOH, secure SW in the commercial market hones the skills of villains, making us all much less safe in the big picture.