LOGBOOK

HELP

Quiz Entry - updated: 2026.08.27

If nobody can be 100% secure, what is a realistic security target for a development project, and which habits get you there?

Not "zero vulnerabilities" but "no well-known vulnerabilities in the code" — reached by knowing the common vulnerability types, avoiding the well-known mistakes, and reusing proven countermeasures and patterns instead of inventing your own.

Perfect security is not an achievable goal for anyone — the defender has to cover every path while an attacker only needs one, and even the most heavily resourced organisations get breached. Setting "100% secure" as the target is therefore worse than useless: it is unmeasurable, so nobody can tell whether the project met it, and it invites the fatalistic conclusion that effort is pointless.

The workable target replaces perfect with no cheap wins for the attacker:

  • Know the types of vulnerabilities. You cannot avoid a class of bug you have never heard of, so a baseline vocabulary of the common failure modes is the entry ticket.
  • Avoid the well-known mistakes. The overwhelming majority of real-world compromises exploit long-documented, long-solved classes of flaw — not novel research.
  • Use proven countermeasures and patterns. Established guidelines and library implementations have already survived the attacks a fresh hand-rolled solution is about to meet for the first time.

Two standing aims follow from that: projects should be "best-of-breed secure" — secure by the best standard the field currently knows, not merely "secure enough for now" — and all developers should be permanently security-aware, because a target that only one specialist carries is one holiday away from lapsing.

Tip: The realistic target is deliberately falsifiable. "Are there known vulnerability classes in our code?" is a question a review can actually answer; "are we secure?" is not.

Go deeper:

From Quiz: SPRG / Security Requirements Fundamentals | Updated: Aug 27, 2026