A few weeks ago, Jim Manico reached out to get information about the history of Application Security, in preparation of a keynote, which he will be giving tomorrow at the OWASP conference.Social engineering and hacking definitely went hand in hand, and the perception many people seemed to have through the early ’90’s was that it was possible to get remote access via an exploit, but privilege escalation was more about getting credentials, either through password cracking or social engineering.Birth of an Industry Frankly, the seed of software security becoming an industry in my view wasn’t the government, despite them having spent decades understanding the core problems and trying to build themselves secure computer systems (they were even using exploitation themselves no later than the mid-’90s).While they didn’t charge for Java, it was immediately clear that the language would be popular for enterprise applications, and the language emphasizing security suggested that companies using the language would start taking application security seriously.Before Java, it seemed like people in the know assumed that getting hacked might be inevitable if you ran a system on the internet, but that it wasn’t likely to be a big deal, and that getting root was far less likely, without some social engineering."