The Register Home Page

back to article CISA: Most exploited vulnerabilities should have been eradicated decades ago

CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited. The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the …

  1. BBRush

    Unless it is cost neutral...

    ... any changes to software production will be ignored.

    Fixing bugs has been "revenue protection" for as long as I can remember and that's a poor, poor cousin to "revenue generation". These days, with the bastardised "agile" workflows and short times to market, that's going to be even more of a push. throw in a statutory duty to maximise revenue and eps for shareholders and it's hard to see why a software company would want to spend all that time/money/effort fixing old crap code (unless they have to).

    Yes, there are exceptions, but they seem to be rare.

  2. Bebu sa Ware Silver badge
    Facepalm

    "How many times can a man turn his head. And pretend that he just doesn't see?"

    "The answer, my friend, is blowin' in the wind. The answer is blowin' in the wind."

    We have known the problems and the solutions for decades but far too much "pretend that he just doesn't see."

    1. just4this Bronze badge

      Re: "How many times can a man turn his head. And pretend that he just doesn't see?"

      But first we need AI powered pedometers to figure out how many roads a man has walked down.

  3. itscomplicated

    Yeah

    Vulnerabilities such as allowing a felon to be elected president.

  4. alain williams Silver badge

    What hits the vendor's bottom line ?

    It is getting something to market: start earning money through sales; get there before the competition does.

    Producing software that is safer or better designed comes a poor second.

    How to fix this ? Maybe product liability along the same lines as for cars, air-planes or medical drugs. But this is hard as software is far more complex than cars and it is far too easy to blame the customer for using it wrongly. The only people to benefit would be lawyers.

    1. jlturriff

      Re: What hits the vendor's bottom line ?

      Well, obviously, voluntary action to secure software falls a distant second to profit-making, so there needs to be a counter-incentive to even things out; perhaps massive fines or prison time for executives whose software products' vulnerabilities can be shown to be caused by negligence would help. At first it would only kick in after a breach or breaches are suffered, but if the penalties are consistently applied the word would quickly get around and compliance would follow. Self-interest is pretty reliable.

  5. Doctor Syntax Silver badge

    "Secure by Design" is one thin - being secure by implementation is a whole extra can of worms.

  6. IGotOut Silver badge

    And it's only going to get worse.

    Vibe coding anyone?

  7. Ken Hagan Gold badge

    No silver bullet

    If the top two bad patterns together account for only one sixth of vulnerabilities, what that tells me is that the situation is complicated and diverse.

    1. Anonymous Coward
      Anonymous Coward

      Re: No silver bullet

      But one of those is one that shouldn't exist today because its at least 20 years old.

      One thing that could be done is once a bug of this type is found in Joe Programmer's code, all of his code gets checked.

  8. Anonymous Coward
    Anonymous Coward

    There are people that just don't understand

    I remember working AT ORACLE and having to explain what a SQL injection was.

    Then getting the response "why would anyone do that?"

    I facepalmed so hard I nearly injured myself.

  9. steelpillow Silver badge

    Not just software

    System architects don't have the will to think about non-functional requirements either. All too often it goes something like:

    "Go talk to the OpSec team, they deal with that."

    "But I just did, and they complained that you never listen."

    "That's between you and them. Oh look, a squirrell..."

    So we turn up shoulder to shoulder:

    "That architectural flaw we were talking about"

    "It's not in the contract. If you want it fixed, you'll have to write it into a new contract. I'm busy. Ah! the coffee timer! Excuse me."

    Scene 3, the contracts office:

    "What's SQL Injection?"

  10. hayzoos

    insecure by design

    So many of the problems are there by intentional design. It is allowed to be by lack of repercussions. An example, targeted ads: requires collecting data individulized so ads can be targeted to individuals. The whole system to support the goals is so complex and intentionally implements many of the problems identified. Cross Site Scripting is the defacto standard of the ad/data collection industry, some of the worst site have hundreds of third-party active content sources pummelling a visitor's browser. All it takes is one of those sources to contain intentionally malicious content (beyond the obvious spying on everything you do), and your session is pwned. The overly complex design of everything allows bad actors to hide in plain sight.

    Other industries are adopting the methods, automotive, appliance, utilities, etc. Some that had traditionally been held to higher standards are successfully shedding those shackles to operate in the fast and loose with consumer data and metadata realm. The cancer is spreading far and wide.

    1. Anonymous Coward
      Anonymous Coward

      Re: insecure by design

      How many of them to propose we remove from the equation? How would you fix it? Every web page has to serve all of its content from the same domain? Easy with a proxy, but not nearly so fast.

      1. just4this Bronze badge

        Re: insecure by design

        Sites need to be

        Fast enough for delivering actual content.

        If they are too slow for ad sites to auction off varying sized sections of the screen you paid for with your money like it was their own property, I’m OK with that.

  11. Taliesinawen Bronze badge

    Vulnerabilities should have been eradicated decades ago

    With todays model that's not possible and no amount of patching is going to fix it. As someone famous who worked in cryptography once said. They had a dream of walking along an endless pebble dashed beach carrying a basket of pebbles. When they came across a similar pebble then they could let one down. Patching is only moved the pebble basket further down the beach.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon