Linked by Mark Tolliver on Thu 13th Sep 2007 08:14 UTC
Thread beginning with comment 271112
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[5]: Response times
by dylansmrjones on Thu 13th Sep 2007 17:54
in reply to "RE[4]: Response times"
If the actual loss in productivity due to reduced functionality overshadows the cost of a potential security breach, then you probably want to reconsider.
That is however not a concern of the company behind the product, but merely a concern of those using the product.
1) It is the responsibility of the developers ( or the company/companies) to deliver a fix here and now.
2) It is the responsibility of the users to decide whether or not to install the fix.
If installing the fix breaks the users software and this is more expensive than a security breach, they shouldn't install the fix. If the security breach is more expensive than reduced functionality, they should install the fix. The developers however only have the responsibility to give the users the choice.
Finding the balance is solely the responsibility of the users.




Member since:
2005-07-06
It is silly to choose compatibility over security. It is wiser to choose reduced functionality than it is to choose reduced security.
That depends entirely on the application and situation. If the actual loss in productivity due to reduced functionality overshadows the cost of a potential security breach, then you probably want to reconsider. You want to find a balance between ease of use and security, taking into account all surrounding factors.