The Impossible Security Goal Your Team Should Set Anyway

Time for a New Year’s Resolution: Your Software Security KPI—A Perfectly Secure Product In The One Thing by Gary Keller and Jay Papasan, the authors explore how long-term goals function as behavior-change mechanisms. They advocate for SMART goals with very low odds of achievement—almost impossible targets. What Would That Goal Look Like for Software Security? Goal: Any security vulnerability finding in any environment by any scan or vendor will be remediated in 60 days. ...

January 7, 2025 · 4 min · Snake Eyes Software

Murphy and The Law of Unintended Consequences

Posted on June 3, 2024 You all know Murphy, right? The one whose law revolves around anything that can go wrong will go wrong. And you probably know the Law of Unintended Consequences: all actions have consequences, whether intentional or unintentional. One of the reasons I have remained in software security is because I have a knack for finding those unintended consequences. This time, I found many of them. In many disparate but related systems. Including myself. ...

June 3, 2024 · 3 min · Snake Eyes Software

Security as an Enabler: The Case for a Hands-On Approach

Posted on March 21, 2024 Overview The traditional “build vs. buy” decision in software development oversimplifies the actual choices teams face. A more nuanced perspective examines the balance between building solutions internally and purchasing external services. Using authentication in “MyOwnTutorial” as a case study reveals how security can function as either a gatekeeper or a facilitator. Three Approaches to Authentication Build: Custom Authentication Solution Security as a Gate: Creating an internal authentication system requires deep security expertise. The approach demands extensive threat modeling, security testing, and compliance validation. While tailored to specific needs, this path creates bottlenecks as security reviews and vulnerability assessments must precede deployment. ...

March 21, 2024 · 2 min · Snake Eyes Software

Tools, Gates, and Debates: Navigating the Quirks of Software Security

Posted on March 13, 2024 In the constantly shifting world of software security, trends fade as quickly as they emerge. Drawing from over two decades in the field, the author identifies three areas where mainstream security guidance falls short. Security Shouldn’t Be a Gate—Or Should It? The old security-as-gatekeeper model restricted release cycles, but the pendulum swung too far the other way. Security serves as a quality checkpoint enabling informed decisions. ...

March 13, 2024 · 2 min · Snake Eyes Software