Schneier: Vendors, not coders, to blame for bugs

Computer security expert Bruce Schneier has waded into a debate over who is to blame for the security flaws that result from poorly coded software.

Last week, former White House cybersecurity advisor Howard Schmidt, launched the debate at a seminar in London. Schmidt argued that programmers should be held responsible for flaws in code they write. "In software development, we need to have personal quality assurances from developers that the code they write is secure," he said.

Schmidt's argument outraged large swathes of software developers, including tech luminaries such as Bruce Schneier, chief technology officer of Counterpane Internet Security. In his blog and in a Wired News column, Schneier took issue with Schmidt's comments, saying that the problem is with the companies selling the software, not with the developers.

Software companies are in the business of making a profit, Schneier argued. "They try to balance the costs of more secure software -- extra developers, fewer features, longer time to market -- against the costs of insecure software: expense to patch, occasional bad press, potential loss of sales," he wrote.

The result, Schneier said, is "lousy software." Companies find money to "weather the occasional press storm" rather than to "design security right from the beginning."

"The end result is that insecure software is common," Schneier argued. "But because users, not software manufacturers, pay the price, nothing improves. Making software manufacturers liable fixes this externality."

Many ZDNet readers seem to agree with Schneier and put the blame for security problems squarely with the vendors selling the software.

The results of a ZDNet online poll, which attracted more than 1,000 respondents, showed that 53 percent of readers who replied felt that the blame lies with vendors. Of the rest, 40 percent said no one is to blame, and just six percent said software programmers were at fault.

As far as Schneier is concerned, "computer security isn't a technological problem -- it's an economic problem."

ZDNet UK's Colin Barker reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured