Memfida
All episodes

Audio

Episode 245 min

Security, better late than never

Alejandro Vallecilla wrote that companies delay security until a merger, an incident or a law forces it. We go through the EU law that makes a security bug a product defect, and what a Security Hub score is worth without a risk assessment.

Chapters

In this episode

  • The article this conversation follows: Security, better late than never, and why Alejandro Vallecilla wrote it
  • The EU Product Liability Directive: software becomes a product, and a security bug that harms a person is a defect the maker pays for without proof of carelessness
  • What counts as harm under that law: injury, private property, personal data destroyed or corrupted. A leak alone is a GDPR matter
  • The Cyber Resilience Act: an exploited vulnerability now has to be reported to the EU within a fixed deadline, with fines scaled to global turnover
  • How large a share of an open source survey had not heard of either law
  • How fast the yearly count of published CVEs is growing, and how much of it is the Linux kernel alone
  • Why “we are too small to be a target” stopped being true once bots and AI agents do the scanning
  • Sepehr Lorestani ten years ago against Sepehr Lorestani now, and when an engineer puts a foot down with the business
  • What junior engineers still have to learn when AI writes the code, and why asking AI the stupid question is the safest place to learn
  • Alejandro Vallecilla on landing in an AWS account with thousands of failing Security Hub controls and no risk assessment behind them
  • Ten controls that matter beat ninety that do not, and why we prefer statistics over a score
  • The inventory that turns a new CVE into a one-hour check instead of a panic
  • A secure environment does not mean you will not be attacked. It means the attacker works harder
  • The ratio between attackers and defenders is out of balance, and why a fine is how it comes back
  • Security is a range, never zero or one. What the Revolut attack shows
  • Containing an attack once it is inside, the topic we left for a follow-up