Secure Coding mailing list archives

Re: Is developer education a lost cause?


From: der Mouse <mouse () Rodents Montreal QC CA>
Date: Sat, 31 Jan 2004 17:47:54 +0000

I believe that developer education is a lost cause.  [...]  It's
because customers don't care.
[...]

Actually, I think this is only partially true.  It's certainly true in
the mass-market end-user millions-of-copies world, but I believe it is
much less true - perhaps to the point of being false - in the
higher-end market where you expect to sell perhaps a few dozen copies.
My contact with that market is minimal, but I did once work at a
company that aimed at it. so this opinion is not _total_ armchair
quarterbacking.

So I think training developers is mostly a waste of time & money.  We
should spend our time instead on convincing software purchasers that
they should care.  Then, and only then, is training developers
worthwhile.

Assuming you're talking about the end-user mass market, I agree with
you - and I think there isn't much we (for any appropriate value of
"we") can do to convince buyers to care.  If sobig and mydoom and such
aren't doing it, what chance do we have?

/~\ The ASCII                           der Mouse
\ / Ribbon Campaign
 X  Against HTML               [EMAIL PROTECTED]
/ \ Email!           7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B






Current thread: