Re: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows
Glynn Clements <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Vel wrote: > Given the drive for faster product cycles combined with outsourcing to > countries that have very low wage costs and above all human greed, does > anyone really think that writing 100% secure code is possible ?? Regardless of whether "100% secure code" is possible (or even a meaningful concept), outsourcing to countries with lower mean incomes would appear to be the best (least bad?) way to reduce overall development costs. The other likely possibilities, namely: a) reducing the number of developer hours, and b) using less skilled (and hence less expensive) developers both have obvious negative implications for the security of the product. Your other points, i.e. the desire for faster product cycles and improved profit margins are both valid. The latter of those not only largely subsumes the outsourcing point, but is more directly relevant. If development costs are the reason for inadequate attention to security, then the specific mechanism (i.e. whether costs are cut by reducing hours, by hiring from lower on the pay scale, or by hiring from countries with lower wages generally) is really just a symptom. Also, the overall process may have substantial costs besides actual development (e.g. marketing, legal, technical support), many of which are tied to income levels in the target market. Consequently, reducing development costs may not greatly reduce costs overall. On the contrary, it's entirely possible that outsourcing could reduce the pressure to cut corners and/or allow the hiring of more experienced programmers without significantly increasing the overall costs. Furthermore, if the market requires support of a nature which can't readily be outsourced (e.g. on-site rather than by telephone), any increase in development costs could be compensated by a reduction in support costs. -- Glynn Clements <[email protected]>