Re: bill gates' claim about security vulnerabilities per LOC inUnix versus Windows

Glynn Clements <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
Vel wrote:

> Given the drive for faster product cycles combined with outsourcing to
> countries that have very low wage costs and above all human greed, does
> anyone really think that writing 100% secure code is possible ??

Regardless of whether "100% secure code" is possible (or even a
meaningful concept), outsourcing to countries with lower mean incomes
would appear to be the best (least bad?) way to reduce overall
development costs.

The other likely possibilities, namely:

a) reducing the number of developer hours, and

b) using less skilled (and hence less expensive) developers

both have obvious negative implications for the security of the
product.

Your other points, i.e. the desire for faster product cycles and
improved profit margins are both valid. The latter of those not only
largely subsumes the outsourcing point, but is more directly relevant.

If development costs are the reason for inadequate attention to
security, then the specific mechanism (i.e. whether costs are cut by
reducing hours, by hiring from lower on the pay scale, or by hiring
from countries with lower wages generally) is really just a symptom.

Also, the overall process may have substantial costs besides actual
development (e.g. marketing, legal, technical support), many of which
are tied to income levels in the target market. Consequently, reducing
development costs may not greatly reduce costs overall.

On the contrary, it's entirely possible that outsourcing could reduce
the pressure to cut corners and/or allow the hiring of more
experienced programmers without significantly increasing the overall
costs. Furthermore, if the market requires support of a nature which
can't readily be outsourced (e.g. on-site rather than by telephone),
any increase in development costs could be compensated by a reduction
in support costs.

-- 
Glynn Clements <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.