frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Time Spent on Hardening

https://third-bit.com/2025/09/18/time-spent-on-hardening/
26•mooreds•1h ago

Comments

esafak•1h ago
Given his experience, I'm surprised that the author is surprised that companies don't know how much time they spend on hardening. Nobody gets paid to do that unless necessary for compliance; companies prefer to build features, and don't track this stuff. Don't even think about asking them to quantify the benefit of hardening.

https://www.wiley.com/en-us/How+to+Measure+Anything+in+Cyber...

actionfromafar•1h ago
It is pretty unknowable.
mathattack•4m ago
I'm huge into measurement, and quantifying this has stumped me. It's one of the few areas I'm willing to surrender and say "Let's just pick a % of time to put on it."

It's bad to say "Let's give it to folks who are underutilized or have capacity" because those are rarely the people who can do it well.

All I can come up with is the hardening % should be in proportion to how catastrophic a failure is, while keeping some faith that well done hardening ultimately pays for itself.

Philip Crosby wrote about this in manufacturing as "Quality is Free" https://archive.org/details/qualityisfree00cros

c2h5oh•1h ago
The time spend on hardening software is always zero or very close to that unless the company makes that hardening a selling point of the product they make.

In the world of VC powered growth race to bigger and bigger chunk of market seems to be the only thing that matters. You don't optimize your software, you throw money at the problem and get more VMs from your cloud provider. You don't work on fault tolerance, you add a retry on FE. You don't carefully plan and implement security, you create a bug bounty.

It sucks and I hate it.

jmclnx•56m ago
Depends upon the software.

I find valgrind easy on Linux and ktrace(1) on OpenBSD easy to use. I do not spend much time, plus I find testing my items on Linux, OpenBSD and NetBSD tends to find most issues without a lot of work and time.

c2h5oh•32m ago
This is not a "companies don't spend enough time with static and dynamic analysis of their software" problem, it's "less than a third of companies I worked or consulted for in the past 20 years mandated having input validation of any kind" problem.
esafak•56m ago
Then you'll get hacked or have an outage, and unless you're a monopoly it will cost you. But will the people who made poor decisions be held accountable?

You can do a decent hardening job without too much effort, if follow some basic guidelines. You just have to be conscientious enough.

c2h5oh•40m ago
I was once told to stop wasting time submitting PRs adding null checks on data submitted via a public API. You know, the kind of checks that prevented said API from crashing if a part of payload was missing. I was told to stop again with my concerns dismissed when I pointed similar things out during code review. I left that company not long after, but it's still around with over a quarter of a billion in funding.

I would love to say that this was an exception during almost 20 years of my professional career, but it wasn't. It was certainly the worst, but also much closer to average experience than it should have been.

juancn•33m ago
Also, depending on the system, time spent on hardening is many times happening concurrently with some other tasks.

Maybe you trigger a load test, or run a soaking test or whatever, while that runs you do something else, pause and check results, metrics, logs, whatever.

If something is funky, you may fix something and try again, get back to your other task and so on.

It's messy, and keeping track of that would add significant cognitive load for little gain.

jimmyl02•28m ago
This metric is typically tracked internally and probably wouldn't be as public because it could indicate how "buggy" a product is. An easy way to measure this is time spent taking incidents from open -> mitigated -> resolved and treating that as time spent * engineers for amount of impact.

The tricky part would be measuring time spent on hardening and making the business decision on how to quantify product features vs reliability (which I know is a false tradeoff because of time spent fixing bugs but still applies at a hand wavy level)

walterbell•27m ago
Why does Nvidia have 50%+ margins on hardware that is price segmented by software/firmware, e.g. Ada (!) in RISC-V security chip? Because their license enforcement has been hardened. How much did 50% margin contribute to 4T valuation?

Less is safer: how Obsidian reduces the risk of supply chain attacks

https://obsidian.md/blog/less-is-safer/
1•saeedesmaili•10s ago•0 comments

Ollama Cloud Models

https://ollama.com/blog/cloud-models
1•monkeydust•32s ago•0 comments

Show HN: New Site for My OSS Digital Signage Toolkit

https://garlic-signage.com/
1•sagiadinos•1m ago•0 comments

Show HN: Zedis – A Redis clone I'm writing in Zig

https://github.com/barddoo/zedis
3•barddoo•6m ago•0 comments

Ask HN: Looking for Pilot Users to Test a New Captcha System?

1•vieews•9m ago•0 comments

Everactive's Self-Powered SoC at Hot Chips 2025

https://chipsandcheese.com/p/everactives-self-powered-soc-at-hot
2•giuliomagnifico•10m ago•0 comments

After 50 years the magic circle (finally) admits Penn and Teller

https://www.nytimes.com/2025/09/19/arts/penn-teller-magic-circle.html
3•wbl•11m ago•0 comments

Lethal Trifecta attack leaking private data in Notion AI agents

https://twitter.com/simonw/status/1969111931152634010
3•abirag•13m ago•0 comments

Trump to announce $100K fee for H-1B specialty visas

https://www.politico.com/news/2025/09/19/trump-to-announce-100k-fee-for-h-1b-specialty-visas-0057...
2•raw_anon_1111•16m ago•1 comments

Wait Smart Glasses Are Suddenly Good? [video]

https://www.youtube.com/watch?v=7gtc1DW2Tgo
2•doener•17m ago•0 comments

2025 Ig Nobel Prize Winners

https://improbable.com/2025/09/18/here-are-the-2025-ig-nobel-prize-winners/
1•NKosmatos•17m ago•0 comments

Rails Needs New Governance

https://davidcel.is/articles/rails-needs-new-governance
4•romellem•21m ago•1 comments

Ted Cruz: MAGA "will regret" what it did to Jimmy Kimmel

https://www.axios.com/2025/09/19/ted-cruz-jimmy-kimmel-fcc-brendan-carr
11•belter•23m ago•1 comments

Will AI have the same adoption challenges as the cloud?

https://substack.com/inbox/post/174054976
2•mathattack•23m ago•0 comments

Five o'clock dinner crowd: why are young Americans eating so early?

https://www.theguardian.com/lifeandstyle/2025/sep/19/gen-z-early-dinner
2•pseudolus•24m ago•2 comments

Is there evidence for exponential quantum advantage in quantum chemistry?

https://arxiv.org/abs/2208.02199
2•felineflock•28m ago•0 comments

Bullying

https://freeyourmindinitiative.com/2025/09/19/bullying/
2•amazonhut•29m ago•0 comments

Google announces expansion of AI features in Chrome

https://arstechnica.com/google/2025/09/google-announces-massive-expansion-of-ai-features-in-chrome/
1•labrador•30m ago•0 comments

Biotic reactions drive post-wetting soil emissions of N2O, NO and CO2

https://www.nature.com/articles/s41598-025-12362-3
2•PaulHoule•31m ago•0 comments

Show HN: Scam Reports from Travelers

https://travelscamwatch.com/
1•TandemApp•34m ago•0 comments

Ivy League nude posture photos

https://en.wikipedia.org/wiki/Ivy_League_nude_posture_photos
3•pessimizer•34m ago•0 comments

AKB48 releases AI-generated single after fans preferred it to human-written song

https://www.cnn.com/2025/09/19/entertainment/akb48-ai-song-japan-scli-intl
1•mikhael•35m ago•0 comments

PSR-20 Clocks: Testable Time in PHP

https://doeken.org/blog/psr-20-clocks-testable-time-in-PHP
2•doekenorg•37m ago•1 comments

Speed of Gravity

https://en.wikipedia.org/wiki/Speed_of_gravity
2•rolph•37m ago•0 comments

GitHub/spec-kit – Toolkit to help you get started with Spec-Driven Development

https://github.com/github/spec-kit
6•chrismustcode•42m ago•1 comments

Emacs China

https://emacs-china.org/
3•Igrom•42m ago•1 comments

A Lawless Nation – Friends don't let friends visit America

https://paulkrugman.substack.com/p/a-lawless-nation
22•xqcgrek2•44m ago•6 comments

Compiled AI #002

https://cmpld.ai/issues/002/
2•mantcz•47m ago•1 comments

Feedmaker: URL + CSS selectors = RSS feed

https://feedmaker.fly.dev
10•mustaphah•47m ago•2 comments

Ask HN: Why not have shoes that are just as loud as sports cars?

1•amichail•50m ago•2 comments