Podcast
Root Causes 473: Does Security Software Lack Creativity?


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
March 28, 2025
Jason reports on a 2024 Black Hat keynote about how modern software development practices inhibit innovation and invention.
Podcast Transcript
Lightly edited for flow and brevity.
We've gotten really, really, really good at adding layers of abstraction between developer teams and subject matter experts. There being this just a lot of abstraction for sometimes very good reasons. It allows developers to think and focus, but it also creates a lack of transparency about what's in the minds of developers, and when you're trying to tackle really tough problems, developing newer or innovative techniques becomes kind of difficult. I think the analogy, one of the analogies that was said very quickly was it’s almost like developers are trying to learn their craft in a library, without being in a classroom, without being in normal, other human settings where there's discussions about how to tackle a problem. It's almost like they're learning how to tackle the problem with just the books that are in front of them, and nothing else. They're off completely on their own and this ability to innovate and solve tough problems, and of course, obviously cyber security software has a lot of these problems to have to solve over the next 5 to 10 years. I just thought, geez, what a really good point. Agile has been amazing for productivity. I don't think it's been amazing for innovation.

