DinisCruz / Book_SecDevOps_Risk_Workflow

Content for 'JIRA Risk Project' book published at LeanPub
Apache License 2.0
56 stars 17 forks source link

Add a joke/true story about "refrigerator" #61

Open securestep9 opened 8 years ago

securestep9 commented 8 years ago

Need to talk about why developers avoid appsec people

DinisCruz commented 8 years ago

Here is the story

"Basically the appsec team was doing static analysis of some big app and they found lots of hardcoded passwords in the source code. The developers were very angry and unhappy about this finding, because this meant their app could not go live in time and they all lost their bonuses . So the developers said: "You AppSec guys are always causing us problems. We hate your guts. So for our next release we are going to rename all the password variables inside our code to "refrigerator" so your stupid SAST tool could no longer find them and flag this as a vulnerability"