• @henfredemars@infosec.pub
      link
      fedilink
      English
      151 month ago

      By not understanding how version control works. I’ve worked at places that had a surprising number of developers who would just merge things in ways that drop code from other developers.

            • @henfredemars@infosec.pub
              link
              fedilink
              English
              21 month ago

              How optimistic. At my last workplace I got us to finally stop using zip files for version control. This was at a fortune 500 company.

              The utility of software is so great that even terrible processes are still functional to some degree.

              • A times B times C equals X. If X is more than the cost of a failure or security breach, we don’t fix the software.

                Are there a lot of these kinds of problems?

                You wouldn’t believe.

                Which Fortune 500 company do you work for?

                A major one.

                • @henfredemars@infosec.pub
                  link
                  fedilink
                  English
                  21 month ago

                  I now work for a small business but in the interest of not getting bitten in the ass I don’t wish to give the name of my previous employer. It was a large defense contractor, but our values didn’t align so I moved on when I found another opportunity to put food on the table. I know that’s not a satisfying answer but I’m here for entertainment value and the opportunity cost might not be worth it. My main point was that even though they have the money they didn’t see the value in good software process.

                  All the time! We would leave bugs unfixed even if the fix was trivially easy because management felt productive listing it as a cost savings. Software maintenance was seen as a necessary evil.

                  • Software maintenance was seen as a necessary evil.

                    The most important lesson I learned about the economics of software is that sourcecode is always accounted as a liability and not an asset. Accountants will never let you code your way into more value. Everything else you see stems from that truth.